animation-composer

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow where the agent ingests untrusted data from user-provided animation specifications to generate and execute Python code. This represents a potential surface for indirect prompt injection.
  • Ingestion points: The skill refers to processing external specification documents such as scenes.md and scene_with_position.md in rules/scene-planning.md and templates/scene-spec-template.md.
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are prescribed for the agent to use when reading these external specifications.
  • Capability inventory: The skill is designed to generate Python scripts and execute them via the manim and manimgl command-line interfaces, providing a path from processed data to code execution.
  • Sanitization: There are no instructions for validating or sanitizing the content of the scene specifications before they are used to generate executable code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:16 PM
Security Audit — agent-trust-hub — animation-composer