manim-reels
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external CSV files containing practice questions, answers, and explanations to generate video content and social media metadata.
- Ingestion points: CSV data sources described in
SKILL.mdandreferences/bulk_csv_reels.mdthat are used for batch reel generation. - Boundary markers: The instructions lack explicit guidance for the agent to use boundary markers or "ignore" directives when interpolating untrusted CSV row content into generation prompts.
- Capability inventory: The skill possesses significant capabilities including the execution of shell commands (
manim,ffmpeg) and the creation of scripts that interact with the local file system. - Sanitization: While the documentation mentions generating "safe question slugs" for filenames, there are no specific requirements to sanitize or escape CSV content before it is processed by the DSPy-based generation agent.
- [DYNAMIC_EXECUTION]: The workflow involves the automated generation of Manim Python scripts which are subsequently executed to produce video artifacts.
- Evidence:
SKILL.md(Step 5/6) andreferences/dspy_reelsgen_agent.mddescribe a pipeline where the agent writes scene logic to.pyfiles and renders them using themanimCLI tool. - [COMMAND_EXECUTION]: The skill requires the execution of multiple command-line utilities for video production and verification.
- Evidence: Routine use of
manim,ffmpeg,ffprobe, andpythoncommands for rendering, stitching media, and checking output specifications. - [EXTERNAL_DOWNLOADS]: The skill documentation refers to external libraries and local tools required for operation.
- Evidence: Instructions to install
manimviapipand the requirement for a local clone of theQwen3-TTSrepository at~/clawd/Qwen-tts-voice-clone.
Audit Metadata