skills/feicaiclub/hyperframes/gsap/Gen Agent Trust Hub

gsap

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/extract-audio-data.py uses subprocess.run to execute the ffmpeg command-line tool. The arguments are passed as a list rather than a shell string, which is the recommended secure practice to prevent shell injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The documentation in references/effects.md contains example <script> tags referencing the GSAP library and its TextPlugin from cdn.jsdelivr.net. This is a well-known and trusted CDN commonly used for serving front-end libraries.
  • [DATA_EXPOSURE]: The skill uses XMLHttpRequest to load local JSON data files. This is a documented requirement for synchronous data loading in the HyperFrames environment and does not involve exfiltration of sensitive information.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 05:53 AM
Security Audit — agent-trust-hub — gsap