animate
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill's workflow instructs the agent to execute a local shell script
scaffold.shwith a project name argument directly influenced by user input. This pattern is vulnerable to command injection if a user provides a specially crafted project name containing shell metacharacters (e.g.,;,&,|). - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted natural language descriptions from users to generate React components and animation logic. It lacks explicit boundary markers or sanitization instructions to differentiate user data from system instructions, which could lead to the generation of malicious code if the input is adversarial.
- Ingestion points: User-provided animation descriptions via
$ARGUMENTSin SKILL.md. - Boundary markers: Absent; user input is directly integrated into the scene planning and code generation process.
- Capability inventory: The skill has access to
Bash,Write, andEdittools, enabling it to execute commands and modify the filesystem based on processed input. - Sanitization: No validation or escaping of the user description is performed before it is used for code generation or API requests.
- [DYNAMIC_EXECUTION]: The skill generates React components, scene templates, and configuration files at runtime based on user descriptions. This generated code is subsequently executed in the user's environment when the project is built and run.
- [EXTERNAL_DOWNLOADS]: The skill relies on
npm installto fetch project dependencies. While NPM is a well-known service, this involves downloading and potentially executing third-party code from a public registry during the project setup. - [COMMAND_EXECUTION]: The workflow requires executing
npm run devto launch a local development server, which executes scripts defined in the generated project context. - [DATA_EXFILTRATION]: The skill sends user-provided descriptions to Google's Gemini API for enhancement if the
GEMINI_API_KEYenvironment variable is available. Google is a recognized trusted organization.
Audit Metadata