design-motion
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines a set of purely instructional design standards and performance optimizations. It does not execute unauthorized commands or access sensitive files.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it processes external layout components and static markup to apply motion effects. * Ingestion points: Static markup and components referenced in SKILL.md. * Boundary markers: Absent; the skill does not explicitly define delimiters for untrusted input data. * Capability inventory: The skill is configured to use Read, Write, Edit, Glob, and Grep tools to modify project files. * Sanitization: None; the skill does not specify sanitization for the inputs it processes. * Note: This finding reflects the inherent functional nature of a code-modification skill and is not indicative of malicious intent.
- [SAFE]: The multi-agent workflow described in the reference files (such as fuse-ai-pilot:research-expert) refers to internal vendor-specific agents belonging to fusengine and does not represent an external threat or remote code execution risk.
Audit Metadata