motion
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes shell scripts (
scripts/init-motion.shandscripts/optimize-bundle.sh) that automate the installation of themotionlibrary using standard package managers (npm,yarn,pnpm,bun). These scripts also create project boilerplate files insrc/components/andsrc/hooks/. All operations are limited to project initialization and configuration. - [EXTERNAL_DOWNLOADS]: The skill references the official
motionpackage and documentation hosted on well-known domains such asmotion.devandgithub.com/motiondivision. It provides standard installation commands for these verified resources. - [PROMPT_INJECTION]: The documentation uses instructional language to guide the AI agent's behavior (e.g., 'Core Rule', 'Critical Rules', 'Escalation Rule'). These are used for architectural guidance and do not attempt to bypass safety filters or override system-level instructions.
- [SAFE]: No evidence of obfuscation, hardcoded credentials, sensitive data exfiltration, or malicious persistence mechanisms was found in the analyzed files.
Audit Metadata