h5p-verify

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and executes the @missing-elements/h5p-verify package and playwright via npx. These resources are owned by the skill's author or are well-known browser automation tools, used here for their intended purpose of package verification.
  • [COMMAND_EXECUTION]: The skill requires the execution of CLI commands to run the verification tool and install browser dependencies. The commands are standard for this utility's use case.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external .h5p archive files, which contain content that could potentially include instructions targeting the agent or the rendering environment.
  • Ingestion points: Reads and executes content from the package.h5p file provided as input.
  • Boundary markers: None explicitly defined in the prompt instructions.
  • Capability inventory: The tool executes a headless Chromium browser to render the package, generates a JSON report, and saves a screenshot to the local filesystem.
  • Sanitization: The skill instructions do not specify sanitization steps, relying on the underlying tool's handling of the H5P runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 01:27 PM
Security Audit — agent-trust-hub — h5p-verify