vanilla-lynx

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches example code bundles from official ByteDance content delivery infrastructure during development and testing.
  • Evidence: assets/examples/external-bundle.lynxml references https://lf3-static.bytednsdoc.com/obj/eden-cn/hkhkeh7nupqbo/rspeedy/example.template.js.
  • [REMOTE_CODE_EXECUTION]: Provides detailed documentation and examples for loading and executing script bundles using framework-specific APIs.
  • Evidence: Found in references/external-runtime.md and assets/examples/external-bundle.lynxml utilizing lynx.fetchBundle and lynx.loadScript.
  • [COMMAND_EXECUTION]: Recommends the use of standard development utilities for local hosting and validation.
  • Evidence: SKILL.md instructs the user to run npx http-server . for runtime validation of artifacts.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an architecture for processing external code and cross-thread data which presents a potential injection surface.
  • Ingestion points: The framework fetches and executes external bundles as described in references/external-runtime.md.
  • Boundary markers: Instructions mandate explicit serializable, JSON-compatible payloads for communication between the main and background threads.
  • Capability inventory: Utilizes lynx.fetchBundle for network operations and lynx.loadScript for execution within the Lynx runtime.
  • Sanitization: Guidance emphasizes the use of serializable primitives and explicitly prohibits passing functions or internal node handles across execution boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:00 AM
Security Audit — agent-trust-hub — vanilla-lynx