fx-firework

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implementation consists of local JavaScript and HTML files that perform canvas-based animations. No external network requests, file system access, or administrative commands are present.
  • [SAFE]: All external references target the author's official GitHub repositories (nexu-io), representing legitimate vendor documentation and source code links.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data via CSS custom properties (e.g., --accent, --ok) and DOM elements. However, these are used strictly for visual rendering parameters (colors, dimensions) and do not flow into any sensitive sinks or command execution paths. The capability inventory is restricted to Canvas 2D API operations. Verdict remains safe as there is no exploitable surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 11:50 AM
Security Audit — agent-trust-hub — fx-firework