ui-animation
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/extract_frames.pyusessubprocess.runto invokeffmpeg. The implementation correctly passes arguments as a list and does not enableshell=True, which is the recommended method for preventing command injection vulnerabilities when handling external file paths. - [EXTERNAL_DOWNLOADS]: The skill requires standard developer tools including
ffmpegand the Python packagesopencv-python,numpy, andscipy. These are well-established libraries appropriate for the skill's functionality of reverse-engineering animations from video recordings. - [SAFE]: A thorough review of the instructions in
SKILL.mdand the reference documentation found no attempts at prompt injection or bypassing safety guidelines. The skill promotes best practices such as accessibility compliance and performance optimization. - [SAFE]: No data exfiltration or credential exposure patterns were identified. The scripts operate on local files provided by the user and do not perform network requests to untrusted domains.
Audit Metadata