faceless-explainer
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests raw user text to produce video scripts and storyboards, presenting an opportunity for embedded malicious instructions to influence the planning phase.\n
- Ingestion points: Raw text from the user is saved to
capture/extracted/visible-text.txtand read by the agent in Step 1 and Step 3.\n - Boundary markers: The instructions do not define delimiters or specific warnings for the LLM to differentiate between data and instructions.\n
- Capability inventory: The skill executes shell commands via
npx, spawns subprocesses forffmpegandffprobe, and performs extensive file system writes.\n - Sanitization: No sanitization or safety filtering of the input text is implemented before agent processing.\n- [COMMAND_EXECUTION]: The workflow involves spawning
ffmpegandffprobefor media processing tasks and running local Node.js scripts for project automation, all of which are consistent with the skill's primary function.\n- [EXTERNAL_DOWNLOADS]: The generated output includes the GSAP animation library from the well-knowncdn.jsdelivr.netCDN and interacts with the HeyGen API for audio generation, which is standard behavior for this utility.
Audit Metadata