launch-video
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository content such as READMEs, documentation, and benchmarks to determine the video story, visual metaphors, and mechanisms. This creates a surface where malicious instructions in a repository could influence the agent's actions.
- Ingestion points: README, documentation, benchmarks, and brand art (SKILL.md).
- Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are used when processing external repository content.
- Capability inventory: The skill has capabilities to generate code, render video/audio (Remotion), write files, and commit changes to the repository.
- Sanitization: No explicit input validation, filtering, or escaping of external content is mentioned.
- [DYNAMIC_EXECUTION]: The skill uses programmatic video generation which involves generating and executing code for rendering and audio synthesis.
- Evidence: The instructions describe synthesizing music in code and utilizing Remotion's frame-by-frame renderer for production (SKILL.md).
Audit Metadata