muapi-cartoon-dance-animation

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the muapi CLI and curl to process animation tasks.\n- [DATA_EXFILTRATION]: The skill makes network requests to api.muapi.ai to transmit image and video data. This domain is the designated service provider for the skill's functionality.\n- [PROMPT_INJECTION]:\n
  • Ingestion points: User-provided image and video URLs are ingested through the user_image and reference_video fields in SKILL.md.\n
  • Boundary markers: No delimiters or instructions are used to isolate these inputs from the surrounding command context.\n
  • Capability inventory: The skill has the capability to execute shell commands (muapi, curl) as detailed in SKILL.md.\n
  • Sanitization: The skill lacks explicit sanitization or validation logic for user-provided URLs before they are interpolated into command-line arguments.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 02:05 PM
Security Audit — agent-trust-hub — muapi-cartoon-dance-animation