hero-video-scrub-apple

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONNO_CODE
Full Analysis
  • [COMMAND_EXECUTION]: The SKILL.md and EVAL.md files contain shell command examples (ffmpeg, grep, bash scripts) for developer use. These are static documentation snippets intended for manual execution or automated testing during development and do not represent a security risk within the skill's execution environment.
  • [EXTERNAL_DOWNLOADS]: The skill fetches the GSAP animation library and ScrollTrigger plugin from the JSDelivr CDN (cdn.jsdelivr.net). JSDelivr is a well-known, established content delivery network. This is a standard practice for web development templates.
  • [DYNAMIC_EXECUTION]: The skill uses createImageBitmap for decoding images. This is a native, high-performance web API that performs decoding off the main thread. It is a recommended security and performance best practice compared to older image loading methods.
  • [SAFE]: The skill follows excellent resource management patterns, including the use of AbortController to cancel pending network requests and bitmap.close() to free up GPU memory when the component is destroyed. This prevents memory leaks and unnecessary network consumption.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 05:48 PM
Security Audit — agent-trust-hub — hero-video-scrub-apple