ljg-card
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
bunto execute several local maintenance and production scripts, such asassets/capture.tsfor rendering images andassets/verify-full-text.tsfor content validation. These executions are constrained to the skill's own codebase and are essential for its operation. - [EXTERNAL_DOWNLOADS]: The skill utilizes the
playwrightpackage and its official browser installer (chromium). These are well-known tools from Microsoft (a trusted vendor) and are used strictly for the rendering process. The skill instructions also emphasize avoiding remote font loads to ensure privacy and stability. - [INDIRECT_PROMPT_INJECTION]: As the skill processes external content (URLs, pasted text) and renders it via HTML, it possesses an inherent attack surface. However, the author has implemented significant defenses: a strict block-by-block comparison tool (
verify-full-text.ts) ensures the rendered output has not been modified or injected with new instructions, and thecapture.tsscript validates the logical structure of complex 'whiteboard' renders against a pre-defined ledger. - [OBFUSCATION]: The
assets/audit.tsscript usesString.fromCharCodeto define search tokens (e.g., 'svg', 'npm') for its internal linting process. This is a benign implementation used to enforce technical constraints (such as preventing the use of vector assets or legacy package managers) within the skill's source files.
Audit Metadata