marketing-demo
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute ply, ffmpeg, and npx commands to automate browser screenshots and process them into video assets as defined in SKILL.md.
- [EXTERNAL_DOWNLOADS]: The skill utilizes npx to download and run the remotion package from the public npm registry for high-quality video rendering.
- [PROMPT_INJECTION]: The skill operates on content from external websites via the ply navigate command, which introduces a potential surface for indirect prompt injection. Evidence chain: 1) Ingestion points: ply navigate (SKILL.md); 2) Boundary markers: Absent; 3) Capability inventory: Bash tool execution (SKILL.md); 4) Sanitization: Absent.
Audit Metadata