enhance-motion

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface by ingesting untrusted data from the repository's source files to perform its audit and enhancement tasks.
  • Ingestion points: The skill reads package.json, CSS files (*.css), and framework component files (*.tsx, *.jsx, *.vue, *.svelte) via cat and rg commands.
  • Boundary markers: There are no explicit instructions to use delimiters or warnings to disregard instructions potentially embedded within the source code being analyzed.
  • Capability inventory: The skill utilizes shell commands (rg, cat), modifies source code files, and performs automated browser testing through playwright-cli.
  • Sanitization: The instructions do not define any sanitization, escaping, or validation protocols for the code content before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill utilizes local command-line utilities (rg, cat) to search and read file contents. While these are intended for legitimate auditing of the codebase, they operate on file paths derived from the repository structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:11 PM
Security Audit — agent-trust-hub — enhance-motion