broll-remotion-build
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data which constitutes a potential indirect prompt injection surface. Ingestion points: SRT files and design documents accessed as primary inputs in SKILL.md and the role prompts. Boundary markers: The instructions lack explicit delimiters or warnings to treat ingested content as untrusted data. Capability inventory: The agent can generate executable HTML/JavaScript source code and invoke shell commands via a local toolchain. Sanitization: There are no documented procedures for sanitizing or validating the content of the external files before they influence code generation.
- [COMMAND_EXECUTION]: The skill requires the execution of a project-local script 'remotion-toolchain.mjs' to manage dependencies and perform heavy rendering tasks.
Audit Metadata