app-preview-craft

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The scripts/doctor.mjs script is designed to automatically execute npm install at runtime if required packages are detected as missing. This fetches and executes code from the external npm registry during the skill's setup phase.
  • [DYNAMIC_EXECUTION]: The skill's rendering engine in scripts/render.mjs utilizes dynamic import() to load custom theme files. If these files have .js or .mjs extensions, the engine executes them as JavaScript. This provides a vector for arbitrary code execution if a user or agent is persuaded to load a malicious theme file.
  • [COMMAND_EXECUTION]: The skill frequently spawns external processes using child_process.spawn and spawnSync. This includes executing ffmpeg and ffprobe for media processing, npm for package management, and system-level commands like open, explorer.exe, or xdg-open to reveal files in the OS file manager. While these are used for primary functionality, they represent a significant execution surface.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data, including screenshots, screen recordings, and JSON project configurations. It lacks explicit boundary markers or sanitization for instructions that might be embedded within the metadata or structure of these files, creating a surface for indirect prompt injection (Ingestion points: scripts/studio.mjs, scripts/render.mjs).
  • [SAFE]: The local web server implemented in scripts/server.mjs includes protections against directory traversal attacks by validating that resolved file paths remain within the intended root directories.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 08:04 AM
Security Audit — agent-trust-hub — app-preview-craft