h5p-normalize

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to fetch and run @missing-elements/h5p-normalize and @missing-elements/h5p-verify. These are vendor packages corresponding to the skill's author, 'missing-elements'.
  • [COMMAND_EXECUTION]: The instructions involve executing shell commands such as npx, curl, and unzip to process H5P archives and verify server header support.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes H5P packages, which are ZIP archives containing user-controllable media and metadata, creating a surface for potential injection attacks.
  • Ingestion points: Files and URLs provided by the user for normalization, as specified in SKILL.md.
  • Boundary markers: None identified; the skill does not explicitly differentiate between its instructions and the data within the H5P files.
  • Capability inventory: Uses npx for tool execution, curl for network diagnostics, and unzip for archive testing, while also writing new .h5p files to the local system.
  • Sanitization: The skill includes basic integrity checks (CRC validation) and stops if damaged entries are encountered.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 01:28 PM
Security Audit — agent-trust-hub — h5p-normalize