create-ugc-heygen
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill package consists of documentation and test specifications with no executable scripts or runtime logic.
- [SAFE]: Analysis of the workflow and configuration files found no malicious patterns, obfuscation, or unauthorized network activity.
- [CREDENTIALS_UNSAFE]: The documentation identifies the requirement for HeyGen credentials and provider details for the intended functionality. No actual secrets or API keys are hardcoded or exposed.
- [PROMPT_INJECTION]: A theoretical surface for indirect prompt injection is identified as the skill is designed to ingest user briefs in
SKILL.md(Workflow Step 1). No boundary markers or sanitization are defined. However, as the skill is currently a non-functional scaffold with capabilities limited to writing manifest files, the risk is negligible.
Audit Metadata