javascript-animation

Warn

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill's workflow involves generating JavaScript code that is executed within a Chromium browser. Additionally, the provided utility scripts (render.mjs, asset-audit.mjs, layout-check.mjs) use createRequire(process.cwd() + '/') to dynamically load the playwright or playwright-core modules. This pattern of loading dependencies from a computed path can be risky if the environment is not strictly controlled.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of a user-supplied 'brief' which is used to generate the animation's code and assets. This creates a surface where malicious instructions in the brief could attempt to manipulate the generated code to bypass security checks or perform unintended operations. The skill includes an asset-audit.mjs script that performs static analysis and runtime network monitoring to detect unauthorized external resource loading, which serves as a mitigation measure.
  • [COMMAND_EXECUTION]: The rendering process relies on executing the ffmpeg utility via child_process.spawn and execFileSync. While the command arguments are structured, the tool operates on files and configurations generated based on user input, creating a chain of execution from untrusted data to system commands.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 30, 2026, 07:54 PM
Security Audit — agent-trust-hub — javascript-animation