scroll-promo-site-builder

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill manages its project dependencies using standard package managers and official registries.\n
  • Evidence: The assets/site-template/package.json file specifies well-known, versioned libraries such as react and vite.\n
  • Evidence: Handoff scripts like assets/handoff-templates/start-mac.command and start-windows.bat include commands to run npm install for setting up the local environment.\n- [COMMAND_EXECUTION]: The workflow incorporates automated scripts to validate and process video assets locally.\n
  • Evidence: scripts/probe_videos.py and scripts/build_review_sequence.py utilize the Python subprocess module to execute ffprobe and ffmpeg for media analysis and concatenation.\n
  • Evidence: Utility shell scripts, including encode_web_video.sh and extract_boundary_frames.sh, use ffmpeg to perform encoding tasks and extract frames for continuity review.\n- [DYNAMIC_EXECUTION]: The skill facilitates the creation and execution of a local web application.\n
  • Evidence: It uses the Vite build tool and development server to provide a local preview of the React-based promo site.\n- [PROMPT_INJECTION]: The skill includes an indirect prompt injection surface as it ingests external product materials and reference webpages.\n
  • Evidence: Step 0 of the workflow in SKILL.md instructs the agent to collect product sources and reference webpages or videos, which are then used to inform the creative process. However, the skill implements strict phase gates and specific model binding requirements that mitigate risks associated with untrusted data ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 02:09 AM
Security Audit — agent-trust-hub — scroll-promo-site-builder