product-launch-video

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Remotion CLI, executing commands such as npx remotion studio for previewing and npx remotion render for final video production.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its data processing workflow:\n
  • Ingestion points: User-provided product details, messages, and voiceover text collected in Phase 0.\n
  • Boundary markers: Absent; user strings are directly integrated into the generated code and storyboard metadata.\n
  • Capability inventory: The agent is instructed to write files to the project directory and execute shell commands for rendering.\n
  • Sanitization: No explicit sanitization or validation of user-provided content is mentioned prior to code interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 03:30 PM
Security Audit — agent-trust-hub — product-launch-video