github-repo-promo

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Employs shell utilities like sips for obtaining screenshot dimensions and curl for sending script data to the ElevenLabs API.
  • [EXTERNAL_DOWNLOADS]: Downloads generated voiceover audio from the ElevenLabs API (a well-known AI service) and utilizes the hyperframes rendering tool via npx.
  • [PROMPT_INJECTION]: The skill processes untrusted external data from GitHub repositories (READMEs and descriptions) to generate narration scripts (SKILL.md, Step 0). This ingestion point lacks explicit boundary markers or sanitization, presenting a potential surface for indirect prompt injection where repository content could attempt to influence the agent's behavior. Capability inventory includes subprocess calls via curl and sips.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 07:28 PM
Security Audit — agent-trust-hub — github-repo-promo