marketing-demo

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute ply, ffmpeg, and npx commands to automate browser screenshots and process them into video assets as defined in SKILL.md.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx to download and run the remotion package from the public npm registry for high-quality video rendering.
  • [PROMPT_INJECTION]: The skill operates on content from external websites via the ply navigate command, which introduces a potential surface for indirect prompt injection. Evidence chain: 1) Ingestion points: ply navigate (SKILL.md); 2) Boundary markers: Absent; 3) Capability inventory: Bash tool execution (SKILL.md); 4) Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 02:06 PM
Security Audit — agent-trust-hub — marketing-demo