scroll-world-storytelling

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust framework for generating landing pages with three distinct rendering modes (Video, Three.js, and HTML/Data). It emphasizes the use of local assets and pinned dependencies (such as local Three.js modules), which significantly reduces the risk of supply chain attacks associated with remote CDNs.
  • [COMMAND_EXECUTION]: The documentation provides an ffmpeg command for optimizing video seeking. This is a standard instructional use of a well-known utility for the skill's primary purpose and does not involve any hidden or malicious execution logic.
  • [EXTERNAL_DOWNLOADS]: Instructions are included for generating video assets via the Grok Imagine Video API. These instructions include safety guardrails, explicitly advising the agent never to spend credits or upload local reference files to the generator without user approval.
  • [DATA_EXFILTRATION]: The skill includes instructions to inspect local design inspiration archives for stylistic guidance. It proactively mitigates exfiltration risks by forbidding the transmission of these local files to external services without explicit user consent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 03:09 AM
Security Audit — agent-trust-hub — scroll-world-storytelling