skills/editframe/skills/vite-plugin/Gen Agent Trust Hub

vite-plugin

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: Local processing of remote media URLs. The JIT transcoding feature allows passing remote URLs to ffprobe through the url parameter. While intended for media metadata extraction, this presents an attack surface where maliciously crafted URLs could potentially exploit vulnerabilities in the underlying tool or network stack.- [DATA_EXFILTRATION]: Local file system access via API parameters. The local File and Asset APIs resolve paths provided in the src parameter relative to a configurable root directory. This pattern is vulnerable to directory traversal (e.g., using ../ sequences) if the input is not strictly sanitized, potentially allowing unauthorized access to sensitive files on the host machine.- [DATA_EXFILTRATION]: Arbitrary file write capability in visual testing endpoints. The /@ef-write-snapshot and related endpoints use testName and snapshotName to construct local file paths for saving image data. This poses a security risk if the parameters are not validated, as it could allow an attacker to overwrite system or project files via path traversal.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 02:33 PM
Security Audit — agent-trust-hub — vite-plugin