skills/lijigang/ljg-skills/ljg-card/Gen Agent Trust Hub

ljg-card

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses bun to execute several local maintenance and production scripts, such as assets/capture.ts for rendering images and assets/verify-full-text.ts for content validation. These executions are constrained to the skill's own codebase and are essential for its operation.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the playwright package and its official browser installer (chromium). These are well-known tools from Microsoft (a trusted vendor) and are used strictly for the rendering process. The skill instructions also emphasize avoiding remote font loads to ensure privacy and stability.
  • [INDIRECT_PROMPT_INJECTION]: As the skill processes external content (URLs, pasted text) and renders it via HTML, it possesses an inherent attack surface. However, the author has implemented significant defenses: a strict block-by-block comparison tool (verify-full-text.ts) ensures the rendered output has not been modified or injected with new instructions, and the capture.ts script validates the logical structure of complex 'whiteboard' renders against a pre-defined ledger.
  • [OBFUSCATION]: The assets/audit.ts script uses String.fromCharCode to define search tokens (e.g., 'svg', 'npm') for its internal linting process. This is a benign implementation used to enforce technical constraints (such as preventing the use of vector assets or legacy package managers) within the skill's source files.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 02:34 AM
Security Audit — agent-trust-hub — ljg-card