motion-frames

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions specify the creation of motion graphics using only HTML and inline CSS animations. By explicitly forbidding JavaScript, the skill minimizes the risk of cross-site scripting (XSS) or other execution-based attacks in the generated artifacts.
  • [INDIRECT_PROMPT_INJECTION]: The workflow involves reading an external DESIGN.md file to determine styling tokens. While this represents a data ingestion surface for potentially untrusted content, the skill's restricted output format (HTML/CSS only) and lack of sensitive capabilities (network, file system access, or command execution) ensure that any injected instructions cannot be successfully weaponized.
  • [NO_CODE]: The skill does not include or install any external code, scripts, or packages, relying entirely on native browser rendering capabilities for its functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 03:51 PM
Security Audit — agent-trust-hub — motion-frames