motion-review
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run
npx remotion renderandbash scripts/qa_frames.sh. These commands execute the code within the video project to generate frames for review. Running project-controlled code or scripts via shell carries inherent risks if the project files are untrusted. - [PROMPT_INJECTION]: The skill ingests content from
.tsxfiles and potentially audio metadata. This creates a surface for indirect prompt injection where an attacker could place malicious instructions in code comments or metadata to influence the agent's behavior during the review or the auto-fix cycle. - Ingestion points:
.tsxcomposition files and rendered.mp4files. - Boundary markers: The instructions do not define delimiters or specific isolation for external content.
- Capability inventory: File system reading, file system writing (for auto-fixes), and shell command execution (
npx,bash,ffprobe). - Sanitization: No validation or sanitization of input file content is specified.
- [DATA_EXFILTRATION]: The skill describes uploading audio files (
.mp3) to an external AI service (genai.upload_file) for transcription and quality verification. This involves transferring project data to a well-known service (Google/Gemini) as part of the intended quality assurance workflow.
Audit Metadata