huashu-seedance
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes instructions for the agent to execute
gitcommands (rev-parse,ls-remote,pull) to manage version updates and check for new releases of the skill from the vendor's repository. - [COMMAND_EXECUTION]: Local engine scripts, such as
engine/frames.mjsandengine/preview.mjs, utilizeexecFileSyncto run system binaries likeffmpegfor frame extraction andnode/npxfor rendering white models. - [EXTERNAL_DOWNLOADS]: The Three.js library is loaded from the well-known JSDelivr CDN (
https://cdn.jsdelivr.net/npm/three@0.181.2/+esm) within theengine/renderer.htmltemplate to facilitate 3D rendering. - [EXTERNAL_DOWNLOADS]: The skill configuration and scripts utilize
npxto download and execute thehyperframespackage from the NPM registry to perform video rendering tasks. - [REMOTE_CODE_EXECUTION]: The skill documentation provides workflows that involve downloading and executing remote code via
git pullfor updates andnpx hyperframesfor rendering, both of which are common practices for development-oriented tools and are targeted at established registries or vendor-owned repositories.
Audit Metadata