motion-graphics

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes Python utility functions in rules/audio-sync.md and rules/web-export.md that utilize subprocess.run to interface with the ffmpeg CLI. These functions are used for media processing tasks such as muxing audio and video, concatenating audio files, and optimizing video for web export. The commands are constructed using lists rather than shell strings, which is a secure practice to mitigate shell injection vulnerabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides templates and rules for generating animations based on user-supplied text (e.g., titles, kinetic typography, and narration scripts), which creates a potential surface for indirect prompt injection.
  • Ingestion points: User-provided text for titles, kinetic typography templates in SKILL.md, and voiceover narration scripts in rules/audio-sync.md.
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are present in the provided templates to isolate user-supplied content from rendering instructions.
  • Capability inventory: The skill utilizes subprocess.run for ffmpeg operations and writes files to the local system through the Manim renderer and FFmpeg utility functions.
  • Sanitization: No explicit sanitization, escaping, or validation of user-provided strings is implemented in the template code before the content is passed to the renderer or external TTS services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:44 AM
Security Audit — agent-trust-hub — motion-graphics