animate
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references and provides implementation guidance for several well-known and trusted third-party libraries including Motion (formerly Framer Motion), GSAP, Anime.js, Lottie, Rive, and Three.js. It also references technical patterns from the trusted Vercel Labs organization's public repositories for View Transitions. All external resources are standard industry tools for the skill's stated purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to read and process user source code to provide animation audits or implementations.
- Ingestion points: Reads local project files such as
package.json, React components, and CSS files using theview_filetool. - Boundary markers: The skill does not explicitly define markers to delimit untrusted user code from instructions, though it operates under a deterministic 8-step build sequence that restricts the scope of its outputs to animation-related code.
- Capability inventory: The skill has access to
view_file,write_to_file, andbashtools across all supported platforms. - Sanitization: There are no explicit sanitization routines for user code, relying on the agent's internal safety guardrails and the specific domain constraints of UI animation.
Audit Metadata