motion-review

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run npx remotion render and bash scripts/qa_frames.sh. These commands execute the code within the video project to generate frames for review. Running project-controlled code or scripts via shell carries inherent risks if the project files are untrusted.
  • [PROMPT_INJECTION]: The skill ingests content from .tsx files and potentially audio metadata. This creates a surface for indirect prompt injection where an attacker could place malicious instructions in code comments or metadata to influence the agent's behavior during the review or the auto-fix cycle.
  • Ingestion points: .tsx composition files and rendered .mp4 files.
  • Boundary markers: The instructions do not define delimiters or specific isolation for external content.
  • Capability inventory: File system reading, file system writing (for auto-fixes), and shell command execution (npx, bash, ffprobe).
  • Sanitization: No validation or sanitization of input file content is specified.
  • [DATA_EXFILTRATION]: The skill describes uploading audio files (.mp3) to an external AI service (genai.upload_file) for transcription and quality verification. This involves transferring project data to a well-known service (Google/Gemini) as part of the intended quality assurance workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — motion-review