narova-3d-production
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements strict path validation using path.relative and realpathSync to ensure that all file operations are confined to the project directory, effectively preventing directory traversal attacks.
- [SAFE]: A built-in secret redaction mechanism (redactSecrets) is used to scan subprocess outputs and remove sensitive environment variable values before they are recorded in diagnostic logs or receipts.
- [SAFE]: Subprocess execution for Blender and FFmpeg is managed with defined timeouts and output capture limits to prevent potential resource exhaustion or denial-of-service through excessive logging.
- [SAFE]: The skill follows security best practices for dependency management, recommending the use of 'npm ci --ignore-scripts' to prevent the execution of potentially malicious lifecycle scripts during installation.
- [SAFE]: Operations that modify the filesystem use atomic write patterns and staging directories, ensuring that target files are only replaced upon successful completion and providing a rollback mechanism in case of failure.
Audit Metadata