web-3d-motion-hero-by-197q59i
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill directs the agent to analyze external media and web content from sites such as GoodCase and X.com using browser or media inspection tools. This establishes a surface for indirect prompt injection, where malicious instructions could be embedded in external content to influence the agent's behavior.
- Ingestion points: External URLs provided in
references/cases.mdand user-supplied requirements inSKILL.md. - Boundary markers: The skill provides a logical boundary by instructing the agent to distinguish observed evidence from its own recommendations.
- Capability inventory: The agent is authorized to produce implementation-ready code, interaction specifications, and component designs.
- Sanitization: There are no explicit instructions for sanitizing or validating content retrieved from external URLs before it is processed.
- [EXTERNAL_DOWNLOADS]: The skill references media assets and font resources from well-known and trusted services, including Twitter (video.twimg.com, pbs.twimg.com) and Google Fonts. These are standard resources for web development workflows and do not escalate the risk profile.
- [REMOTE_CODE_EXECUTION]: The skill involves the generation of executable code using common industry frameworks such as React, Tailwind CSS, and Framer Motion. This is a low-risk behavior associated with the skill's primary purpose of providing implementation-ready design artifacts.
Audit Metadata