review-animations

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a local shell script (scripts/verify.sh) to perform automated audits of animation properties. The script utilizes standard tools like grep or rg to identify anti-patterns such as transition: all or scale(0) entrances.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and critique untrusted code diffs and components. This creates an attack surface where malicious instructions could be embedded within code comments or strings in the processed data.
  • Ingestion points: Code diffs and UI components provided by the user for review (as specified in SKILL.md).
  • Boundary markers: No explicit delimiters or instructions to ignore embedded content are used when processing the code.
  • Capability inventory: The skill executes local search commands (scripts/verify.sh) and generates detailed markdown reports based on findings.
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the input code before it is analyzed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:57 AM
Security Audit — agent-trust-hub — review-animations