animated-landing-pages

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill instructs the agent to use external layout references and media URLs as context for generating frontend implementation code.
    • Ingestion points: Visual references (images/screenshots) and media URLs from services like Higgfield or Pinterest are processed to influence layout and asset code (referenced in references/workflow.md and references/prompt-library.md).
    • Boundary markers: The provided prompt templates lack explicit delimiters or instructions to ignore embedded commands within the references.
    • Capability inventory: The skill has the capability to generate and modify application code (React, Tailwind) and perform file system writes (downloading assets).
    • Sanitization: No content validation or sanitization is defined for the external references before they are used in prompts.
  • [EXTERNAL_DOWNLOADS]: Resource Acquisition. The skill workflow involves downloading media assets (e.g., Higgfield-generated videos, CloudFront-hosted assets) to local repository storage for production stability.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 09:29 AM
Security Audit — agent-trust-hub — animated-landing-pages