app-preview-craft
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
scripts/doctor.mjsscript is designed to automatically executenpm installat runtime if required packages are detected as missing. This fetches and executes code from the external npm registry during the skill's setup phase. - [DYNAMIC_EXECUTION]: The skill's rendering engine in
scripts/render.mjsutilizes dynamicimport()to load custom theme files. If these files have.jsor.mjsextensions, the engine executes them as JavaScript. This provides a vector for arbitrary code execution if a user or agent is persuaded to load a malicious theme file. - [COMMAND_EXECUTION]: The skill frequently spawns external processes using
child_process.spawnandspawnSync. This includes executingffmpegandffprobefor media processing,npmfor package management, and system-level commands likeopen,explorer.exe, orxdg-opento reveal files in the OS file manager. While these are used for primary functionality, they represent a significant execution surface. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data, including screenshots, screen recordings, and JSON project configurations. It lacks explicit boundary markers or sanitization for instructions that might be embedded within the metadata or structure of these files, creating a surface for indirect prompt injection (Ingestion points:
scripts/studio.mjs,scripts/render.mjs). - [SAFE]: The local web server implemented in
scripts/server.mjsincludes protections against directory traversal attacks by validating that resolved file paths remain within the intended root directories.
Audit Metadata