codeart2d
Warn
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Multiple Python scripts (fx_build.py, rig_animate.py, parallax_build.py, codeart_core.py) use the subprocess module to execute external binaries and sibling skill scripts. For example, codeart_core.py invokes chrome or resvg-js-cli for SVG rasterization, while fx_build.py and rig_animate.py invoke build_animation_clips.py and node to run verification scripts.
- [DYNAMIC_EXECUTION]: The skill employs several dynamic execution techniques. fx_verify.mjs uses the JavaScript import() function to dynamically load a generated runtime module (fx-runtime.mjs) for verification. forge_core.py uses importlib.import_module to programmatically check for the presence of required Python dependencies. Additionally, forge_core.py and codeart_core.py use ctypes to load system libraries (libc, version.dll) for atomic file operations and file version checking.
- [PRIVILEGE_ESCALATION]: In codeart_core.py, the --no-sandbox flag is added to the Chrome command line if the process is detected to be running as root on Linux. While common for headless browser operation in containerized environments, this explicitly bypasses a security boundary.
- [EXTERNAL_DOWNLOADS]: The skill's documentation and runtime error messages in forge_core.py instruct users to download and install external packages from public registries like PyPI and NPM, specifically resvg-py, Pillow, and @resvg/resvg-js-cli.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-supplied data (PixelSpec JSON, SVG files, layout specs) and uses this data to drive complex logic, write files, and execute shell commands.
- Ingestion points: Spec files processed by render_pixelspec.py, svg_render.py, fx_build.py, and layout_build.py.
- Boundary markers: Validation is performed using JSON schemas via forge_schema.py.
- Capability inventory: File system writes, shell command execution (subprocess.run), and dynamic code loading (fx_verify.mjs).
- Sanitization: Implements some sanitization such as regex checks for identifiers and finite number validation for geometric parameters.
Audit Metadata