motion-broll
Warn
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/make_pages.pyutilizesos.system()andos.popen()to callffmpegandffprobe. While these currently operate on paths managed by the skill, the use of string interpolation for shell commands is a risky pattern that could be exploited if file naming conventions were influenced by external input. - [DYNAMIC_EXECUTION]: The skill's core functionality relies on generating HTML fragments containing JavaScript logic which are subsequently executed using Playwright in
engine/render.jsandengine/beats.js. This runtime execution of agent-generated code is a dynamic execution pattern. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted transcript data which influences agent behavior.
- Ingestion points:
scripts/words.pyreads user-provided SRT/VTT transcript files. - Boundary markers: Absent; transcripts are parsed directly into timing data used for planning.
- Capability inventory: File writing, shell command execution (ffmpeg), and package installation.
- Sanitization: Absent; transcript text is used directly for planning logic in Step 4.
- [EXTERNAL_DOWNLOADS]: The skill installs several external dependencies during setup and runtime.
- Evidence:
scripts/setup.shexecutesnpm install playwrightandnpx playwright install chromium.SKILL.mdinstructs the agent to installfaster-whisperandnumpyviapip.
Audit Metadata