animation-engineer
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes dynamic context injection (using the
!commandsyntax) inSKILL.mdto executecatcommands on local project files and shared protocols such as.forgewright/settings.mdandskills/_shared/protocols/ux-protocol.md. These commands are used to automatically populate the skill's context with relevant project data and organizational standards at load time. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it interpolates the content of external files into its prompt context without using boundary markers or sanitization.
- Ingestion points: Content is ingested from files including
.forgewright/codebase-context.md,.forgewright/settings.md, and multiple shared protocol files inskills/_shared/(identified inSKILL.md). - Boundary markers: The skill lacks delimiters or specific instructions to the agent to ignore any malicious commands that might be embedded within the ingested files.
- Capability inventory: The skill is designed to autonomously implement complex animation systems, including creating and modifying source code in the
src/directory across multiple phases. - Sanitization: No validation or filtering logic is present to sanitize the content read from these local files before it is processed by the agent.
Audit Metadata