skills/prisma-labs-dev/skills/motion/Gen Agent Trust Hub

motion

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes shell scripts (scripts/init-motion.sh and scripts/optimize-bundle.sh) that automate the installation of the motion library using standard package managers (npm, yarn, pnpm, bun). These scripts also create project boilerplate files in src/components/ and src/hooks/. All operations are limited to project initialization and configuration.
  • [EXTERNAL_DOWNLOADS]: The skill references the official motion package and documentation hosted on well-known domains such as motion.dev and github.com/motiondivision. It provides standard installation commands for these verified resources.
  • [PROMPT_INJECTION]: The documentation uses instructional language to guide the AI agent's behavior (e.g., 'Core Rule', 'Critical Rules', 'Escalation Rule'). These are used for architectural guidance and do not attempt to bypass safety filters or override system-level instructions.
  • [SAFE]: No evidence of obfuscation, hardcoded credentials, sensitive data exfiltration, or malicious persistence mechanisms was found in the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 04:35 AM
Security Audit — agent-trust-hub — motion