review-animations
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to analyze untrusted frontend code diffs and animation snippets, creating an indirect prompt injection surface where malicious instructions could be embedded in code comments or string literals to influence the agent's behavior.
- Ingestion points: Frontend CSS/JS code diffs and animation configuration files.
- Boundary markers: The instructions lack explicit delimiters or instructions to ignore embedded commands in user-provided code.
- Capability inventory: The skill is configured for review output only and possesses no tool execution, file-writing, or network capabilities.
- Sanitization: No filtering or validation of the input code is performed before processing.
- [PROMPT_INJECTION]: A metadata discrepancy exists where the skill frontmatter identifies the author as 'Emil Kowalski', which differs from the vendor context of 'sickn33'. While the skill is marked as a community submission, this inconsistency could be misleading regarding the provenance of the instructions.
Audit Metadata