design-motion-principles

Warn

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill points to an external repository at https://github.com/kylezantos/design-motion-principles for its full implementation. This source is not associated with a trusted organization or verified vendor.- [REMOTE_CODE_EXECUTION]: The documentation provides an installation command npx skills add kylezantos/design-motion-principles which retrieves and executes code from a third-party GitHub account. This represents an unvetted remote dependency.- [PROMPT_INJECTION]: The 'Audit' mode ingests untrusted data in the form of existing UI animation code.
  • Ingestion points: User-provided animations and UI code processed during the 'audit animation' and 'motion review' tasks.
  • Boundary markers: There are no explicit markers or 'ignore' instructions defined in the provided file to mitigate the risk of instructions embedded in the audited code.
  • Capability inventory: The skill is capable of generating HTML reports and creating interactive components based on its logic.
  • Sanitization: No input sanitization or validation mechanisms are described in the skill definition.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 13, 2026, 10:44 AM
Security Audit — agent-trust-hub — design-motion-principles