linkedin-launch-video
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the hyperframes package from the npm registry and fetches the GSAP animation library from the jsDelivr CDN.- [COMMAND_EXECUTION]: Uses the Bash tool to execute npx commands for initializing the HyperFrames project, linting code, and rendering the final video asset.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it fetches and processes untrusted content from the web to determine brand identity.
- Ingestion points: Data enters the agent context through WebFetch operations in references/brand-identity.md and SKILL.md.
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands are used when processing fetched content.
- Capability inventory: The skill possesses extensive capabilities including Bash command execution, file writing/editing, and network access via LinkedIn Ads and Cogny MCP tools.
- Sanitization: There is no evidence of sanitization or validation of the external content before it is used to influence the agent's creative or technical output.
Audit Metadata