chengfeng-visual

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates primarily on local project files (e.g., visuals.json, subtitles.json) and uses bundled assets, minimizing external attack vectors.
  • [COMMAND_EXECUTION]: It executes commands using a project-specific CLI tool (videocut-cli.cjs) to manage visual frames and modules. These operations are essential to the skill's purpose and are conducted in a controlled manner.
  • [SAFE]: The included JavaScript libraries (GSAP 3.15.0 and Rough.js) are stored locally as minified vendor files. No suspicious code or hidden network calls were found within these dependencies.
  • [SAFE]: The skill instructions emphasize adherence to technical contracts and quality gates, including automated verification of animation states, which is a security-positive practice.
  • [SAFE]: No evidence of prompt injection, unauthorized data access, or persistence mechanisms was found across the 40 analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 01:09 AM
Security Audit — agent-trust-hub — chengfeng-visual