fx-constellation

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a canvas-based 'constellation' animation. All code is localized to visual rendering and standard DOM interactions.
  • [DATA_EXPOSURE]: No hardcoded credentials or access to sensitive local files were found. The script reads CSS variables for styling purposes, which is standard behavior for design systems.
  • [REMOTE_CODE_EXECUTION]: No external dependencies are installed or executed. The project references official repositories from the vendor (nexu-io) for documentation and upstream source, which is consistent with the skill's stated purpose.
  • [COMMAND_EXECUTION]: No shell commands, subprocess calls, or privilege escalation attempts were detected.
  • [OBFUSCATION]: The code is written in plain JavaScript without any encoding, hidden characters, or deceptive naming conventions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 11:50 AM
Security Audit — agent-trust-hub — fx-constellation