product-launch-video

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill references the ~/.heygen configuration file to authenticate with the HeyGen API for narration and music generation. This is a standard credential path for the vendor's integration and is necessary for primary functionality.\n- [DYNAMIC_EXECUTION]: The scripts assemble-index.mjs, captions.mjs, and transitions.mjs dynamically generate HTML and JavaScript files at runtime to build the final video composition. These scripts use templates and storyboard data to construct GSAP animations.\n- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection by processing external URLs and user scripts. It mitigates this by sanitizing video element attributes (like onerror) during the assembly phase and using isolated packets for sub-agent communication.\n- [COMMAND_EXECUTION]: The skill uses spawnSync to execute local commands such as ffmpeg, ffprobe, and the npx hyperframes CLI to process media assets and manage project state.\n- [EXTERNAL_DOWNLOADS]: The skill fetches the GSAP library from cdn.jsdelivr.net with SRI integrity checks and interacts with HeyGen APIs for media generation. It also uses the npx hyperframes CLI, which is a vendor-owned resource.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:57 PM
Security Audit — agent-trust-hub — product-launch-video