github-repo-promo
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Employs shell utilities like sips for obtaining screenshot dimensions and curl for sending script data to the ElevenLabs API.
- [EXTERNAL_DOWNLOADS]: Downloads generated voiceover audio from the ElevenLabs API (a well-known AI service) and utilizes the hyperframes rendering tool via npx.
- [PROMPT_INJECTION]: The skill processes untrusted external data from GitHub repositories (READMEs and descriptions) to generate narration scripts (SKILL.md, Step 0). This ingestion point lacks explicit boundary markers or sanitization, presenting a potential surface for indirect prompt injection where repository content could attempt to influence the agent's behavior. Capability inventory includes subprocess calls via curl and sips.
Audit Metadata