alterlab-genai-motion-designer
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill encourages high autonomy by instructing the agent to research updates and read project files independently, which can lead to the agent following malicious instructions found in untrusted external data without user oversight.
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface:
- Ingestion points: The agent is instructed to search the web for platform updates and read existing project files (briefs, guidelines, asset inventories) in the 'Workflow' section.
- Boundary markers: No delimiters or instructions to ignore embedded commands are present to protect the agent from data-based attacks.
- Capability inventory: The skill utilizes file-read, file-write, and web-search capabilities across its workflow.
- Sanitization: There is no evidence of validation or filtering for external content retrieved from search results or user files before it is processed or used to generate new files.
Audit Metadata