huashu-seedance

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes instructions for the agent to execute git commands (rev-parse, ls-remote, pull) to manage version updates and check for new releases of the skill from the vendor's repository.
  • [COMMAND_EXECUTION]: Local engine scripts, such as engine/frames.mjs and engine/preview.mjs, utilize execFileSync to run system binaries like ffmpeg for frame extraction and node/npx for rendering white models.
  • [EXTERNAL_DOWNLOADS]: The Three.js library is loaded from the well-known JSDelivr CDN (https://cdn.jsdelivr.net/npm/three@0.181.2/+esm) within the engine/renderer.html template to facilitate 3D rendering.
  • [EXTERNAL_DOWNLOADS]: The skill configuration and scripts utilize npx to download and execute the hyperframes package from the NPM registry to perform video rendering tasks.
  • [REMOTE_CODE_EXECUTION]: The skill documentation provides workflows that involve downloading and executing remote code via git pull for updates and npx hyperframes for rendering, both of which are common practices for development-oriented tools and are targeted at established registries or vendor-owned repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:31 AM
Security Audit — agent-trust-hub — huashu-seedance