motion-graphics
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes Python utility functions in
rules/audio-sync.mdandrules/web-export.mdthat utilizesubprocess.runto interface with theffmpegCLI. These functions are used for media processing tasks such as muxing audio and video, concatenating audio files, and optimizing video for web export. The commands are constructed using lists rather than shell strings, which is a secure practice to mitigate shell injection vulnerabilities. - [INDIRECT_PROMPT_INJECTION]: The skill provides templates and rules for generating animations based on user-supplied text (e.g., titles, kinetic typography, and narration scripts), which creates a potential surface for indirect prompt injection.
- Ingestion points: User-provided text for titles, kinetic typography templates in
SKILL.md, and voiceover narration scripts inrules/audio-sync.md. - Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are present in the provided templates to isolate user-supplied content from rendering instructions.
- Capability inventory: The skill utilizes
subprocess.runforffmpegoperations and writes files to the local system through the Manim renderer and FFmpeg utility functions. - Sanitization: No explicit sanitization, escaping, or validation of user-provided strings is implemented in the template code before the content is passed to the renderer or external TTS services.
Audit Metadata