javascript-animation
Warn
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill's workflow involves generating JavaScript code that is executed within a Chromium browser. Additionally, the provided utility scripts (
render.mjs,asset-audit.mjs,layout-check.mjs) usecreateRequire(process.cwd() + '/')to dynamically load theplaywrightorplaywright-coremodules. This pattern of loading dependencies from a computed path can be risky if the environment is not strictly controlled. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of a user-supplied 'brief' which is used to generate the animation's code and assets. This creates a surface where malicious instructions in the brief could attempt to manipulate the generated code to bypass security checks or perform unintended operations. The skill includes an
asset-audit.mjsscript that performs static analysis and runtime network monitoring to detect unauthorized external resource loading, which serves as a mitigation measure. - [COMMAND_EXECUTION]: The rendering process relies on executing the
ffmpegutility viachild_process.spawnandexecFileSync. While the command arguments are structured, the tool operates on files and configurations generated based on user input, creating a chain of execution from untrusted data to system commands.
Audit Metadata