motion-broll

Warn

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/make_pages.py utilizes os.system() and os.popen() to call ffmpeg and ffprobe. While these currently operate on paths managed by the skill, the use of string interpolation for shell commands is a risky pattern that could be exploited if file naming conventions were influenced by external input.
  • [DYNAMIC_EXECUTION]: The skill's core functionality relies on generating HTML fragments containing JavaScript logic which are subsequently executed using Playwright in engine/render.js and engine/beats.js. This runtime execution of agent-generated code is a dynamic execution pattern.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted transcript data which influences agent behavior.
  • Ingestion points: scripts/words.py reads user-provided SRT/VTT transcript files.
  • Boundary markers: Absent; transcripts are parsed directly into timing data used for planning.
  • Capability inventory: File writing, shell command execution (ffmpeg), and package installation.
  • Sanitization: Absent; transcript text is used directly for planning logic in Step 4.
  • [EXTERNAL_DOWNLOADS]: The skill installs several external dependencies during setup and runtime.
  • Evidence: scripts/setup.sh executes npm install playwright and npx playwright install chromium. SKILL.md instructs the agent to install faster-whisper and numpy via pip.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 25, 2026, 05:03 PM
Security Audit — agent-trust-hub — motion-broll