pr-to-video
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data (PR titles, bodies, and diffs) via
scripts/fetch-pr.mjsandscripts/ingest.mjs. This data is used by the orchestrator and sub-agents to generate video content and scripts. Whileingest.mjsincludes basic sanitization by stripping HTML comments, there is a risk that malicious instructions in the PR data could influence the agent's behavior during the multi-step video creation process. The skill usesJSON.stringifywhen embedding this data into generated JavaScript, which mitigates many script injection risks. - Ingestion points:
scripts/fetch-pr.mjs(fetches PR data via GitHub CLI),scripts/ingest.mjs(processes PR JSON and Diff). - Boundary markers: Present; the skill uses markers in
STORYBOARD.mdand strips HTML comments to prevent hidden instructions in PR templates from being executed. - Capability inventory: File system write access, execution of
npx hyperframesCLI, and local script execution vianode. - Sanitization:
scripts/ingest.mjsemploys acleanBodyfunction to strip HTML comments and truncate long descriptions.scripts/captions.mjsusesJSON.stringifyto escape ingested text before embedding it in JavaScript. - [DYNAMIC_EXECUTION]: The skill dynamically generates executable content at runtime.
scripts/assemble-index.mjsandscripts/captions.mjsconstructindex.htmlandcaptions.htmlby injecting data and GSAP animation logic into templates. This generated code is executed by the video rendering engine. This falls under the category of simple script generation from known templates. - [COMMAND_EXECUTION]: The skill executes multiple external commands including
gh(GitHub CLI) for fetching PR details,npx hyperframesfor project management and video rendering, andffmpeg/ffprobefor audio processing and looping. - [EXTERNAL_DOWNLOADS]: The skill fetches external resources during its workflow.
scripts/fetch-people-avatars.mjsdownloads contributor avatars from GitHub's official domains (github.com,githubusercontent.com). Additionally,scripts/captions.mjsinjects script tags referencing the GSAP library hosted on the well-known servicecdn.jsdelivr.net.
Audit Metadata