h5p-normalize
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npxto fetch and run@missing-elements/h5p-normalizeand@missing-elements/h5p-verify. These are vendor packages corresponding to the skill's author, 'missing-elements'. - [COMMAND_EXECUTION]: The instructions involve executing shell commands such as
npx,curl, andunzipto process H5P archives and verify server header support. - [INDIRECT_PROMPT_INJECTION]: The skill processes H5P packages, which are ZIP archives containing user-controllable media and metadata, creating a surface for potential injection attacks.
- Ingestion points: Files and URLs provided by the user for normalization, as specified in
SKILL.md. - Boundary markers: None identified; the skill does not explicitly differentiate between its instructions and the data within the H5P files.
- Capability inventory: Uses
npxfor tool execution,curlfor network diagnostics, andunzipfor archive testing, while also writing new.h5pfiles to the local system. - Sanitization: The skill includes basic integrity checks (CRC validation) and stops if damaged entries are encountered.
Audit Metadata