chengfeng-visual
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates primarily on local project files (e.g., visuals.json, subtitles.json) and uses bundled assets, minimizing external attack vectors.
- [COMMAND_EXECUTION]: It executes commands using a project-specific CLI tool (
videocut-cli.cjs) to manage visual frames and modules. These operations are essential to the skill's purpose and are conducted in a controlled manner. - [SAFE]: The included JavaScript libraries (GSAP 3.15.0 and Rough.js) are stored locally as minified vendor files. No suspicious code or hidden network calls were found within these dependencies.
- [SAFE]: The skill instructions emphasize adherence to technical contracts and quality gates, including automated verification of animation states, which is a security-positive practice.
- [SAFE]: No evidence of prompt injection, unauthorized data access, or persistence mechanisms was found across the 40 analyzed files.
Audit Metadata