motion-graphics

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes system utilities including ffmpeg, ffprobe, and base64 via Node.js child_process modules to perform video encoding, image metadata extraction, and data encoding tasks.
  • [EXTERNAL_DOWNLOADS]: The skill dynamically loads various frontend libraries (GSAP, MapLibre GL) and geographic datasets (world-atlas) from the JSDelivr CDN. These resources are standard dependencies for the skill's mapping and animation capabilities.
  • [DATA_EXFILTRATION]: The locate.mjs utility transmits image data to the Google Gemini API (generativelanguage.googleapis.com) to facilitate automated object localization. This functionality is documented as an optional feature requiring a valid GEMINI_API_KEY or GOOGLE_API_KEY.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface for untrusted external data, including web page screenshots and DOM captures fetched via the hyperframes capture command. These assets are used as background layers and coordinate sources for animations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — motion-graphics