ray-so-code-snippet
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches configuration and available styling options from Raycast's official GitHub repository (
raw.githubusercontent.com/raycast/ray-so). This is a trusted source used for legitimate configuration purposes. - [COMMAND_EXECUTION]: Uses
curlto fetch theme/language lists andagent-browserto navigate to the generated ray.so URL and capture images. These actions are aligned with the skill's primary purpose. - [COMMAND_EXECUTION]: Executes Python snippets for URL encoding and
base64commands for data processing. These are standard utility operations. - [REMOTE_CODE_EXECUTION]: While it injects a library (
html-to-image) into the browser context viajsdelivr.net, this is a common and necessary pattern for the intended screenshot functionality and targets a well-known CDN.
Audit Metadata