pr-to-video

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data (PR titles, bodies, and diffs) via scripts/fetch-pr.mjs and scripts/ingest.mjs. This data is used by the orchestrator and sub-agents to generate video content and scripts. While ingest.mjs includes basic sanitization by stripping HTML comments, there is a risk that malicious instructions in the PR data could influence the agent's behavior during the multi-step video creation process. The skill uses JSON.stringify when embedding this data into generated JavaScript, which mitigates many script injection risks.
  • Ingestion points: scripts/fetch-pr.mjs (fetches PR data via GitHub CLI), scripts/ingest.mjs (processes PR JSON and Diff).
  • Boundary markers: Present; the skill uses markers in STORYBOARD.md and strips HTML comments to prevent hidden instructions in PR templates from being executed.
  • Capability inventory: File system write access, execution of npx hyperframes CLI, and local script execution via node.
  • Sanitization: scripts/ingest.mjs employs a cleanBody function to strip HTML comments and truncate long descriptions. scripts/captions.mjs uses JSON.stringify to escape ingested text before embedding it in JavaScript.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates executable content at runtime. scripts/assemble-index.mjs and scripts/captions.mjs construct index.html and captions.html by injecting data and GSAP animation logic into templates. This generated code is executed by the video rendering engine. This falls under the category of simple script generation from known templates.
  • [COMMAND_EXECUTION]: The skill executes multiple external commands including gh (GitHub CLI) for fetching PR details, npx hyperframes for project management and video rendering, and ffmpeg/ffprobe for audio processing and looping.
  • [EXTERNAL_DOWNLOADS]: The skill fetches external resources during its workflow. scripts/fetch-people-avatars.mjs downloads contributor avatars from GitHub's official domains (github.com, githubusercontent.com). Additionally, scripts/captions.mjs injects script tags referencing the GSAP library hosted on the well-known service cdn.jsdelivr.net.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — pr-to-video