product-launch-video

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data by crawling user-supplied URLs to extract text and assets for video generation.
  • Ingestion points: External content is captured in Step 1 (SKILL.md) and stored in files like capture/extracted/visible-text.txt for storyboard and script generation.
  • Boundary markers: The workflow enforces multiple manual approval gates (Step 0, Step 3, and Step 6) where the user must confirm the project plan, storyboard, and final render.
  • Capability inventory: The workflow utilizes file-writing, sub-agent dispatching, and command execution for media processing.
  • Sanitization: The scripts/assemble-index.mjs file contains defensive logic in the hoistApprovedVideos function that explicitly whitelists safe HTML attributes for hoisted media elements, protecting the host page from script injection (e.g., stripping onerror or srcdoc) that might be present in generated frame components.
  • [COMMAND_EXECUTION]: The skill frequently executes local scripts and system binaries to process media files.
  • Evidence: scripts/assemble-index.mjs uses spawnSync to run ffmpeg for audio looping and ffprobe for duration metadata extraction. Other scripts handle duration syncing and asset staging via shell commands.
  • [EXTERNAL_DOWNLOADS]: The skill updates itself from remote sources and fetches assets from well-known services.
  • Evidence: SKILL.md includes commands like npx hyperframes skills update which fetches the latest skill definitions. It also downloads the GSAP animation library from a trusted CDN (jsDelivr) with subresource integrity checks.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 03:53 AM
Security Audit — agent-trust-hub — product-launch-video