skills/changeflowhq/skills/animator/Gen Agent Trust Hub

animator

Fail

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/record.js script is vulnerable to shell command injection. The output file path, which is derived from user-controlled command-line arguments, is concatenated directly into an ffmpeg command string and executed via child_process.execSync. Because the command is executed in a shell, a malicious filename containing shell metacharacters (e.g., ;, `, $(...)) would lead to arbitrary command execution on the host system.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a persistent memory feature that instructs the agent to read and append to ~/.claude/skills/animator/LEARNED.md at the start of every task. This creates a surface for indirect prompt injection where malicious instructions could be persisted in the agent's long-term memory via crafted input or feedback, influencing its behavior across future sessions without the user's knowledge.
  • Ingestion points: The agent is instructed to read LEARNED.md at the beginning of every task.
  • Boundary markers: None. The content is read as authoritative instructions.
  • Capability inventory: The skill has access to shell execution via record.js and doctor.js, as well as file write access via SKILL.md instructions.
  • Sanitization: No sanitization or validation is performed on the content written to or read from the memory file.
  • [PERSISTENCE]: The automatic logging of 'learnings' to a local file serves as a persistence mechanism for agent instructions. If an attacker successfully poisons this file through indirect injection, the malicious instructions will persist across all subsequent uses of the skill.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 8, 2026, 11:41 PM