enhance-motion
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface by ingesting untrusted data from the repository's source files to perform its audit and enhancement tasks.
- Ingestion points: The skill reads
package.json, CSS files (*.css), and framework component files (*.tsx,*.jsx,*.vue,*.svelte) viacatandrgcommands. - Boundary markers: There are no explicit instructions to use delimiters or warnings to disregard instructions potentially embedded within the source code being analyzed.
- Capability inventory: The skill utilizes shell commands (
rg,cat), modifies source code files, and performs automated browser testing throughplaywright-cli. - Sanitization: The instructions do not define any sanitization, escaping, or validation protocols for the code content before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill utilizes local command-line utilities (
rg,cat) to search and read file contents. While these are intended for legitimate auditing of the codebase, they operate on file paths derived from the repository structure.
Audit Metadata