animate

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's workflow instructs the agent to execute a local shell script scaffold.sh with a project name argument directly influenced by user input. This pattern is vulnerable to command injection if a user provides a specially crafted project name containing shell metacharacters (e.g., ;, &, |).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted natural language descriptions from users to generate React components and animation logic. It lacks explicit boundary markers or sanitization instructions to differentiate user data from system instructions, which could lead to the generation of malicious code if the input is adversarial.
  • Ingestion points: User-provided animation descriptions via $ARGUMENTS in SKILL.md.
  • Boundary markers: Absent; user input is directly integrated into the scene planning and code generation process.
  • Capability inventory: The skill has access to Bash, Write, and Edit tools, enabling it to execute commands and modify the filesystem based on processed input.
  • Sanitization: No validation or escaping of the user description is performed before it is used for code generation or API requests.
  • [DYNAMIC_EXECUTION]: The skill generates React components, scene templates, and configuration files at runtime based on user descriptions. This generated code is subsequently executed in the user's environment when the project is built and run.
  • [EXTERNAL_DOWNLOADS]: The skill relies on npm install to fetch project dependencies. While NPM is a well-known service, this involves downloading and potentially executing third-party code from a public registry during the project setup.
  • [COMMAND_EXECUTION]: The workflow requires executing npm run dev to launch a local development server, which executes scripts defined in the generated project context.
  • [DATA_EXFILTRATION]: The skill sends user-provided descriptions to Google's Gemini API for enhancement if the GEMINI_API_KEY environment variable is available. Google is a recognized trusted organization.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 01:02 PM
Security Audit — agent-trust-hub — animate