unicorn-studio

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides templates for generating HTML embed codes that incorporate user-provided values such as project IDs and JSON source URLs. This represents a potential surface where a user could provide a malicious URL during the interaction, but the skill itself maintains safe practices and provides standard development guidelines.
  • Ingestion points: Project IDs and JSON source URLs provided by users to the agent for embed generation.
  • Boundary markers: None explicitly defined in the template snippets.
  • Capability inventory: Generation of HTML snippets containing script references and attributes.
  • Sanitization: Not applicable at the instruction level; implementation relies on the agent's standard output formatting.
  • [EXTERNAL_DOWNLOADS]: The instructions and documentation refer to the official Unicorn Studio domain and standard content delivery networks for loading the animation SDK. These are legitimate resources for the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:54 PM
Security Audit — agent-trust-hub — unicorn-studio