lottiefiles-animation-workflows

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads and processes external animation document data via the engine_document tool to determine its state and apply changes. This creates a potential surface where malicious instructions embedded within a document could attempt to influence the agent's behavior.
  • Ingestion points: Animation document content accessed via engine_document (SKILL.md).
  • Boundary markers: The skill does not define specific delimiters for untrusted document content, though it instructs the agent to make the 'smallest requested change'.
  • Capability inventory: engine_exec (modifies documents), engine_export (writes files/assets), engine_job_result (inspects async output).
  • Sanitization: No explicit sanitization or filtering of document content is mentioned, although instructions prohibit exposing credentials or private data.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 08:58 AM