animated-asset

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill requires access to sensitive file paths containing API keys, specifically ~/.fal/key and ~/.fal/config.toml, to authenticate with the fal.ai service.
  • [COMMAND_EXECUTION]: The workflow involves running several local Python scripts and C++ binaries (e.g., concept.py, run_creature.py, voxelizer) to process the 3D assets.
  • [DYNAMIC_EXECUTION]: The rigging process dynamically executes Python modules found within the tools/rig/clips/ directory using the exec() function.
  • [INDIRECT_PROMPT_INJECTION]: The skill interpolates user-supplied text ("idea") into prompt templates for external AI models, creating a potential vector for indirect prompt injection attacks.
  • Ingestion points: The --idea argument passed to concept.py in SKILL.md and processed via fal_client.py.
  • Boundary markers: The prompt templates lack explicit delimiters or instructions to the model to ignore embedded user commands.
  • Capability inventory: The skill uses exec(), subprocess execution of scripts and binaries, and makes network requests via curl and MCP tools.
  • Sanitization: No evidence of input validation or sanitization for user-provided strings before interpolation.
  • [EXTERNAL_DOWNLOADS]: The skill fetches generated assets (images, 3D models) from external CDN URLs hosted on fal.run.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 05:18 AM
Security Audit — agent-trust-hub — animated-asset