remix-apple-notes-ad-from-sample

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs local command execution to record animations and encode video files. It utilizes ffmpeg for video processing and npx playwright for recording browser-based typing animations. It also runs local Node.js scripts (clips/record-master.js) to coordinate the rendering process.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves brand assets, project metadata, and ad templates from the vendor's (gooseworks-ai) backend using MCP tools. It also interacts with a vendor-managed proxy for ElevenLabs audio generation and may prompt the user to install standard dependencies if missing.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from ad templates and user-supplied angles to generate new ad copy. This risk is mitigated by a mandatory human-in-the-loop approval gate (Phase 1.5) where the agent must present the drafted script for user review before proceeding to rendering or publication.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 03:06 PM
Security Audit — agent-trust-hub — remix-apple-notes-ad-from-sample