product-launch-video
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill references the
~/.heygenconfiguration file to authenticate with the HeyGen API for narration and music generation. This is a standard credential path for the vendor's integration and is necessary for primary functionality.\n- [DYNAMIC_EXECUTION]: The scriptsassemble-index.mjs,captions.mjs, andtransitions.mjsdynamically generate HTML and JavaScript files at runtime to build the final video composition. These scripts use templates and storyboard data to construct GSAP animations.\n- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection by processing external URLs and user scripts. It mitigates this by sanitizingvideoelement attributes (likeonerror) during the assembly phase and using isolated packets for sub-agent communication.\n- [COMMAND_EXECUTION]: The skill usesspawnSyncto execute local commands such asffmpeg,ffprobe, and thenpx hyperframesCLI to process media assets and manage project state.\n- [EXTERNAL_DOWNLOADS]: The skill fetches the GSAP library fromcdn.jsdelivr.netwith SRI integrity checks and interacts with HeyGen APIs for media generation. It also uses thenpx hyperframesCLI, which is a vendor-owned resource.
Audit Metadata