skills/hk-hub/agentskills/archify/Gen Agent Trust Hub

archify

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill implements a robust validation layer using AJV pre-compiled standalone validators for all diagram types. It enforces strict schemas with 'additionalProperties: false', preventing the ingestion of malformed or malicious data structures.
  • [SAFE]: Output security is prioritized through a consistent entity-escaping mechanism. All user-controlled strings (labels, titles, sublabels) are escaped before being rendered in SVG or HTML templates, effectively mitigating Cross-Site Scripting (XSS) and injection risks.
  • [SAFE]: System command execution (Node.js, Git, FFmpeg, and Chrome) is handled securely via argument arrays in child_process.spawn and spawnSync. This prevents shell interpolation and command injection vulnerabilities. Local repository verification includes explicit path sanitization to block directory traversal and access to sensitive metadata.
  • [EXTERNAL_DOWNLOADS]: The diagram template references Google Fonts via a public CDN to provide consistent typography. This reference is documented as safe, targeting a well-known and trusted service.
  • [SAFE]: The interactive viewer logic provided in the assets uses restricted communication patterns (loopback-only preview server) and secure storage (localStorage for preferences), maintaining a clear security boundary for the generated artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:31 PM
Security Audit — agent-trust-hub — archify