faceless-explainer

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests raw user text to produce video scripts and storyboards, presenting an opportunity for embedded malicious instructions to influence the planning phase.\n
  • Ingestion points: Raw text from the user is saved to capture/extracted/visible-text.txt and read by the agent in Step 1 and Step 3.\n
  • Boundary markers: The instructions do not define delimiters or specific warnings for the LLM to differentiate between data and instructions.\n
  • Capability inventory: The skill executes shell commands via npx, spawns subprocesses for ffmpeg and ffprobe, and performs extensive file system writes.\n
  • Sanitization: No sanitization or safety filtering of the input text is implemented before agent processing.\n- [COMMAND_EXECUTION]: The workflow involves spawning ffmpeg and ffprobe for media processing tasks and running local Node.js scripts for project automation, all of which are consistent with the skill's primary function.\n- [EXTERNAL_DOWNLOADS]: The generated output includes the GSAP animation library from the well-known cdn.jsdelivr.net CDN and interacts with the HeyGen API for audio generation, which is standard behavior for this utility.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — faceless-explainer