weread-year-in-review-video-template

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the GSAP animation library from cdn.jsdelivr.net and a preview video asset from repo-assets.open-design.ai. Both sources are well-known services for content delivery and asset hosting in this context.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to populate the template with user-provided reading statistics, notes, and keywords. This ingestion of untrusted data into an HTML artifact represents a theoretical injection surface.
  • Ingestion points: Data is interpolated into the HTML structure in index.html (copied from assets/template.html).
  • Boundary markers: None identified in the prompt instructions for data interpolation.
  • Capability inventory: The skill requires file_write to generate the final HTML artifact.
  • Sanitization: Not explicitly defined in the provided instructions; however, the output is a static HTML composition intended for MP4 rendering.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:53 AM
Security Audit — agent-trust-hub — weread-year-in-review-video-template