animator
Fail
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/record.jsscript is vulnerable to shell command injection. The output file path, which is derived from user-controlled command-line arguments, is concatenated directly into anffmpegcommand string and executed viachild_process.execSync. Because the command is executed in a shell, a malicious filename containing shell metacharacters (e.g.,;,`,$(...)) would lead to arbitrary command execution on the host system. - [INDIRECT_PROMPT_INJECTION]: The skill implements a persistent memory feature that instructs the agent to read and append to
~/.claude/skills/animator/LEARNED.mdat the start of every task. This creates a surface for indirect prompt injection where malicious instructions could be persisted in the agent's long-term memory via crafted input or feedback, influencing its behavior across future sessions without the user's knowledge. - Ingestion points: The agent is instructed to read
LEARNED.mdat the beginning of every task. - Boundary markers: None. The content is read as authoritative instructions.
- Capability inventory: The skill has access to shell execution via
record.jsanddoctor.js, as well as file write access viaSKILL.mdinstructions. - Sanitization: No sanitization or validation is performed on the content written to or read from the memory file.
- [PERSISTENCE]: The automatic logging of 'learnings' to a local file serves as a persistence mechanism for agent instructions. If an attacker successfully poisons this file through indirect injection, the malicious instructions will persist across all subsequent uses of the skill.
Recommendations
- AI detected serious security threats
Audit Metadata