lovstudio-any2deck

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a secure document conversion workflow. It uses local scripts for specialized tasks like branding and merging, ensuring that data processing remains within the expected environment.
  • [COMMAND_EXECUTION]: The skill executes internal TypeScript and Python scripts using standard runtimes (Node.js/Bun and Python 3). These scripts are used for image manipulation and document merging. User-supplied content is sanitized into kebab-case slugs before being used in directory paths, mitigating command injection risks.
  • [EXTERNAL_DOWNLOADS]: The Node.js dependencies (sharp, pptxgenjs, pdf-lib) are industry-standard packages for media and document handling. The skill is installed through the vendor's official toolchain, maintaining a clear chain of trust.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 06:51 AM
Security Audit — agent-trust-hub — lovstudio-any2deck