motion-graphics

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from webpages, news articles, and tweets. This content is ingested by the Director and Builder subagents to generate layouts and animations. A malicious source could attempt to embed instructions to manipulate the agent's output or tool usage.
  • Ingestion points: External content is fetched in the source phase (via media-use or hyperframes capture) and stored in assets/ and shot-plan.json.
  • Boundary markers: The skill relies on subagent logic in agents/director.md and agents/builder.md to interpret data, but specific prompt boundary markers are not defined within this skill's instructions.
  • Capability inventory: The skill can execute shell commands (ffmpeg), perform network requests (fetch to Gemini API), and run browser automation (puppeteer).
  • Sanitization: The skill mentions SVG sanitization for Figma imports but does not detail sanitization for other external content types.
  • [COMMAND_EXECUTION]: The skill frequently executes system binaries like ffmpeg and ffprobe for media processing and npx for tool updates and component installation. While these are executed via array-based arguments (execFileSync, spawnSync) which mitigates basic shell injection, they represent a significant capability applied to external assets.
  • [DYNAMIC_EXECUTION]: The bake-basemap.mjs script uses Puppeteer to render map imagery. It dynamically generates an HTML wrapper and executes JavaScript within a headless browser (launched with the --no-sandbox flag) to capture frames of the map. This browser environment interacts with external tile providers (Esri, CARTO) based on parameters that could be influenced by the agent's planning phase.
  • [EXTERNAL_DOWNLOADS]: The skill downloads and executes code from several well-known and trusted sources. It uses npx to fetch components from the hyperframes registry and includes libraries such as GSAP, MapLibre GL, and TopoJSON via the jsDelivr CDN in its rendering templates. It also sends image data to Google's Gemini API for object localization.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 04:05 AM
Security Audit — agent-trust-hub — motion-graphics