motion-react

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of prompt injection or instructions to bypass safety guidelines was found. The skill uses standard triggers related to animation functionality.
  • [DATA_EXPOSURE_EXFILTRATION]: No hardcoded credentials, sensitive file paths, or unauthorized network operations were detected. The skill focuses entirely on UI animation documentation.
  • [OBFUSCATION]: No signs of Base64 encoding, zero-width characters, homoglyphs, or other obfuscation techniques were identified in the text or code snippets.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns or piped shell commands were found. The skill documentation references standard package installation via pnpm for a well-known library.
  • [COMMAND_EXECUTION]: The skill does not contain instructions for executing arbitrary or dangerous system commands. All code examples are restricted to React UI logic.
  • [PRIVILEGE_ESCALATION]: No commands for privilege escalation (e.g., sudo, chmod) or system-level modifications were found.
  • [PERSISTENCE]: No persistence mechanisms, such as modification of shell profiles or scheduled tasks, were detected.
  • [METADATA_POISONING]: The metadata fields (name, description, author) are consistent with the skill's stated purpose of providing documentation for the Motion library.
  • [INDIRECT_PROMPT_INJECTION]: The skill does not process untrusted external data in a way that would create a vulnerability. It is a static documentation resource.
  • [DYNAMIC_EXECUTION]: No unsafe dynamic execution patterns (e.g., eval, exec, or runtime compilation of untrusted strings) were found. The library's animate API is used for UI transitions as intended.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill does not use any dynamic shell injection syntax in its instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — motion-react