weread-year-in-review-video-template
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the GSAP animation library from
cdn.jsdelivr.netand a preview video asset fromrepo-assets.open-design.ai. Both sources are well-known services for content delivery and asset hosting in this context. - [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to populate the template with user-provided reading statistics, notes, and keywords. This ingestion of untrusted data into an HTML artifact represents a theoretical injection surface.
- Ingestion points: Data is interpolated into the HTML structure in
index.html(copied fromassets/template.html). - Boundary markers: None identified in the prompt instructions for data interpolation.
- Capability inventory: The skill requires
file_writeto generate the final HTML artifact. - Sanitization: Not explicitly defined in the provided instructions; however, the output is a static HTML composition intended for MP4 rendering.
Audit Metadata