composition
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines mechanisms to ingest external data for video customization through
window.EF_RENDER_DATAand remote caption files via thecaptions-srcattribute. This establishes a surface where untrusted data could influence agent actions or rendering output. 1. Ingestion points:window.EF_RENDER_DATA,captions-srcattribute,captions-scriptID. 2. Boundary markers: Not specified. 3. Capability inventory: JavaScript execution viainitializerandaddFrameTaskon temporal elements. 4. Sanitization: Not explicitly documented; implementers are responsible for input validation. - [DYNAMIC_EXECUTION]: The composition model permits custom JavaScript to be executed on a per-frame basis using
initializerandaddFrameTaskhooks to drive animations and computed state within the rendering pipeline. - [EXTERNAL_DOWNLOADS]: The skill utilizes several official Node.js packages under the
@editframescope and references configuration settings for the vendor's API host and media signing services.
Audit Metadata