Back to skill

Security audit

pixel2motion

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with logo animation, but it needs review because its HTML generators can turn untrusted SVG or CSS input into executable browser content.

Use this skill only with logos, SVGs, and motion.css files you trust, and review generated HTML before opening or publishing it. Pin and verify dependencies in controlled environments, and avoid publishing generated pages that contain confidential or unlicensed brand assets.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/animate_svg_html.py:92
Finding

Inline Script Injection Through Unsafely Serialized SVG Content

Content
View full analysis
str: payload = json.dumps(svg_data, ensure_ascii=False, separators=(",", ":")) safe_title = re.sub(r"[<>]", "", title) max_width = max_width_for(svg_data) display_width = display_width_for(max_width) duration_attr = f' data-p2m-duration="{duration_hint}"' if duration_hint else "" indented_css = "\n".join(" " + line if line.strip() else line for line in motion_css.splitlines()) ``` ```html
Remediation
View remediation
", "\\u003e") .replace("&", "\\u0026") .replace("\u2028", "\\u2028") .replace("\u2029", "\\u2029") ) ``` Escaping every `<` is stronger than replacing only `... ``` The JSON must still escape `<` to prevent premature element termination. 3. Validate the parsed SVG against an allowlist of required tags and attributes. Reject active or externally referencing content such as: - `script` - `foreignObject` - Event-handler attributes such as `onload` - `javascript:` URLs - Unexpected external `href` or `xlink:href` values 4. Add regression tests using SVG text containing entity-encoded ``, `

T09 · Insecure Skill Coding Practices

Error
Location
scripts/animate_svg_showcase.py:104
Finding

Generated HTML Injection Through Unescaped Motion CSS

Content
View full analysis
` element. Indentation does not perform contextual escaping or validation. HTML parsing rules take precedence over CSS parsing rules. Therefore, a CSS input containing a case-insensitive closing style sequence such as: ```html ``` will terminate the generated style element. The following attacker-controlled script element will then be parsed and executed by the browser. The existing validation only checks for a ne ...[truncated 1224 chars]
Remediation
View remediation
`, ``, and markup embedded inside comments. Confirm generation is rejected safely. ]]>

T08 · Insecure Dependencies

Warning
Location
README.md:143
Finding

Unpinned Third-Party Python and Browser Dependencies

Content
View full analysis
URLs with another real-browser tool." ) ``` ### Technical Analysis The documented installation commands resolve mutable latest versions of Pillow, NumPy, Playwright, and a Playwright-managed Chromium build. No lock file, exact version constraints, hash verification, or reviewed browser revision is provided. This prevents reproducible installation and exposes users to upstream compromise, unexpected dependency changes, and future compatibility regressions. Although the package names are legitimate and no malicious dependency was identified during this audit, the installation process does not guarantee that users receive the same reviewed artifacts. ### Attack Path 1. A user follows the setup instructions. 2. `pip` queries the configured package index and resolves whatever package versions are current at installation time. 3. Playwright subsequently downloads the browser revision selected by that mutable Playwright version. 4. If an upstream package, package ...[truncated 752 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (19)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
and the centerline survive, so `motion.css` is reusable and only re-packaging (`animate_svg_showcase.py`) plus the Final Frame Contract re-check are needed.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
and the centerline survive, so `motion.css` is reusable and only re-packaging (`animate_svg_showcase.py`) plus the Final Frame Contract re-check are needed.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

md
and the centerline survive, so `motion.css` is reusable and only re-packaging (`animate_svg_showcase.py`) plus the Final Frame Contract re-check are needed.

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · docs/index.html (reported line 4783)May include surrounding context.

html
Vbee7nmtNbGYm7grS2oLP5iNOpGTnWm507alPhd0HCEas3Fv5lWpvj5Yt2QlK/XlfW2b6tdwb61lJ04XNnaNS+06Njb0p/yd1ORjHG7N5J1VnX0w9gMXrDNZTfTVuJo3lnpy5jYYCnXipQ/SKUalS57efxUYSpqDlFruquS4nTTVmZT5sT16676fttrHbXSu3umL21s69xcTu7p11WuKlWo5uU+2ajyk4wXCXywj+1mQYerFu7z+s2z0el+yd1/wDEO2pa07ZpetY0tCIm+opsHh9zNmb7cjH4ml/CrQ1H46ndU6f62vjYtu5oTaaThCLlXTak4unJR7fcm3HX/ZYd1OPG2Ok2/wDw1z//ALOC1r6nO52uNGZ7RWR2z0vRtNQYy6xderSrXHfCnXpSpylHmXHKUm1ycilonbs3raNMZ9DG7FztZ1I6VqQqT/R+qLiOmshTj28Tp3U4wpNuSfaoV1Rm2uHxCS54b5ulPPNgvcs8zj7ynPtnb3VKrFr6pxmmv+Q9DJ3LHOzFPGlMfXzujcbp9SWpKVOvcvGaRqPTdjRrQUPblbScbl8JtPuuPeak/Lh2c8cKKmB6bfTFjtE6Gob66vxMKmp9TU5Twzrwl3Y/GSXEZwjJLtqV1zLvXPNJ01FpTmnWHe3l3mMpc5G6l3XF9XnWm395zk23/Oz0BaS0zjNF6Vw2jsIqix2Bx9vjLRVJd01RoU404dzSXL7Yrl8I7knprEQ5j/K0y5YAEVlcXXF0Obh6w3epa92L0YspQ1VSnXzNpQuLe2jbZCDXfWbqypwSrKSk/LbqRqyf4kZj9PLafffZLS+q9C7uaQlhsXWvaGTw8vj7O57q04ShcxboVZyj4p27Sfj8XHnnmXQNTeZjTEUiJ2jh1/bvVdpenPMLGX07XMarqw0/YzpqLlCNZSlcS4flL4eFaKkvMZTg1w+GVfdMmx1XqD3iwm3sPiaWMnJ3uZuaHiVtj6XDqyUu2SjKTcacG0131I

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
80% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · docs/index.html (reported line 4783)May include surrounding context.

html
<figure class="cell cell-pixel">
        <figcaption class="cell-label"><i class="dot dot-pixel"></i>Pixel</figcaption>
        <div class="pixel-stage" style="height:300px">
          <img class="pixel-img" src="data:image/jpeg;base64,/9j/4AAQSkZJRgABAQAAAQABAAD/4gHYSUNDX1BST0ZJTEUAAQEAAAHIAAAAAAQwAABtbnRyUkdCIFhZWiAH4AABAAEAAAAAAABhY3NwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAA9tYAAQAAAADTLQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAlkZXNjAAAA8AAAACRyWFlaAAABFAAAABRnWFlaAAABKAAAABRiWFlaAAABPAAAABR3dHB0AAABUAAAABRyVFJDAAABZAAAAChnVFJDAAABZAAAAChiVFJDAAABZAAAAChjcHJ0AAABjAAAADxtbHVjAAAAAAAAAAEAAAAMZW5VUwAAAAgAAAAcAHMAUgBHAEJYWVogAAAAAAAAb6IAADj1AAADkFhZWiAAAAAAAABimQAAt4UAABjaWFlaIAAAAAAAACSgAAAPhAAAts9YWVogAAAAAAAA9tYAAQAAAADTLXBhcmEAAAAAAAQAAAACZmYAAPKnAAANWQAAE9AAAApbAAAAAAAAAABtbHVjAAAAAAAAAAEAAAAMZW5VUwAAACAAAAAcAEcAbwBvAGcAbABlACAASQBuAGMALgAgADIAMAAxADb/2wBDAAMCAgICAgMCAgIDAwMDBAYEBAQEBAgGBgUGCQgKCgkICQkKDA8MCgsOCwkJDRENDg8QEBEQCgwSExIQEw8QEBD/2wBDAQMDAwQDBAgEBAgQCwkLEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBD/wAARCAHrA4QDASIAAhEBAxEB/8QAHgABAAIBBQEBAAAAAAAAAAAAAAgJBwEEBQYKAgP/xABeEAACAQMDAwIEAgQHCAkQCwAAAQIDBAUGBxEIEiEJExQiMUEyURUjYXEWM4GRtLXUFxhCUnKVpNEZJGKCoaWxs8EmKDhTV2ZzhZKTlJaistPkQ0VGVmN1doSGwtL/xAAcAQEBAQEBAAMBAAAAAAAAAAAAAwIBBAUGBwj/xAAqEQEAAgIBAwMDBAMBAAAAAAAAAQIDESESMTIEBUEGEyJRYXGBBxSRI//aAAwDAQACEQMRAD8AtTAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
...[truncated 27 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
80% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · docs/index.html (reported line 4783)May include surrounding context.

html
<figure class="cell cell-pixel">
        <figcaption class="cell-label"><i class="dot dot-pixel"></i>Pixel</figcaption>
        <div class="pixel-stage" style="height:300px">
          <img class="pixel-img" src="data:image/jpeg;base64,/9j/4AAQSkZJRgABAQAAAQABAAD/4gHYSUNDX1BST0ZJTEUAAQEAAAHIAAAAAAQwAABtbnRyUkdCIFhZWiAH4AABAAEAAAAAAABhY3NwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAA9tYAAQAAAADTLQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAlkZXNjAAAA8AAAACRyWFlaAAABFAAAABRnWFlaAAABKAAAABRiWFlaAAABPAAAABR3dHB0AAABUAAAABRyVFJDAAABZAAAAChnVFJDAAABZAAAAChiVFJDAAABZAAAAChjcHJ0AAABjAAAADxtbHVjAAAAAAAAAAEAAAAMZW5VUwAAAAgAAAAcAHMAUgBHAEJYWVogAAAAAAAAb6IAADj1AAADkFhZWiAAAAAAAABimQAAt4UAABjaWFlaIAAAAAAAACSgAAAPhAAAts9YWVogAAAAAAAA9tYAAQAAAADTLXBhcmEAAAAAAAQAAAACZmYAAPKnAAANWQAAE9AAAApbAAAAAAAAAABtbHVjAAAAAAAAAAEAAAAMZW5VUwAAACAAAAAcAEcAbwBvAGcAbABlACAASQBuAGMALgAgADIAMAAxADb/2wBDAAMCAgICAgMCAgIDAwMDBAYEBAQEBAgGBgUGCQgKCgkICQkKDA8MCgsOCwkJDRENDg8QEBEQCgwSExIQEw8QEBD/2wBDAQMDAwQDBAgEBAgQCwkLEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBD/wAARCAHrA4QDASIAAhEBAxEB/8QAHgABAAIBBQEBAAAAAAAAAAAAAAgJBwEEBQYKAgP/xABeEAACAQMDAwIEAgQHCAkQCwAAAQIDBAUGBxEIEiEJExQiMUEyURUjYXEWM4GRtLXUFxhCUnKVpNEZJGKCoaWxs8EmKDhTV2ZzhZKTlJaistPkQ0VGVmN1doSGwtL/xAAcAQEBAQEBAAMBAAAAAAAAAAAAAwIBBAUGBwj/xAAqEQEAAgIBAwMDBAMBAAAAAAAAAQIDESESMTIEBUEGEyJRYXGBBxSRI//aAAwDAQACEQMRAD8AtTAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
...[truncated 27 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
80% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · docs/index.html (reported line 6350)May include surrounding context.

html
<figure class="cell cell-pixel">
        <figcaption class="cell-label"><i class="dot dot-pixel"></i>Pixel</figcaption>
        <div class="pixel-stage" style="height:360px">
          <img class="pixel-img" src="data:image/jpeg;base64,/9j/4AAQSkZJRgABAQAAAQABAAD/4gHYSUNDX1BST0ZJTEUAAQEAAAHIAAAAAAQwAABtbnRyUkdCIFhZWiAH4AABAAEAAAAAAABhY3NwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAA9tYAAQAAAADTLQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAlkZXNjAAAA8AAAACRyWFlaAAABFAAAABRnWFlaAAABKAAAABRiWFlaAAABPAAAABR3dHB0AAABUAAAABRyVFJDAAABZAAAAChnVFJDAAABZAAAAChiVFJDAAABZAAAAChjcHJ0AAABjAAAADxtbHVjAAAAAAAAAAEAAAAMZW5VUwAAAAgAAAAcAHMAUgBHAEJYWVogAAAAAAAAb6IAADj1AAADkFhZWiAAAAAAAABimQAAt4UAABjaWFlaIAAAAAAAACSgAAAPhAAAts9YWVogAAAAAAAA9tYAAQAAAADTLXBhcmEAAAAAAAQAAAACZmYAAPKnAAANWQAAE9AAAApbAAAAAAAAAABtbHVjAAAAAAAAAAEAAAAMZW5VUwAAACAAAAAcAEcAbwBvAGcAbABlACAASQBuAGMALgAgADIAMAAxADb/2wBDAAMCAgMCAgMDAwMEAwMEBQgFBQQEBQoHBwYIDAoMDAsKCwsNDhIQDQ4RDgsLEBYQERMUFRUVDA8XGBYUGBIUFRT/2wBDAQMEBAUEBQkFBQkUDQsNFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBT/wAARCAJqBMQDASIAAhEBAxEB/8QAHgABAAICAgMBAAAAAAAAAAAAAAgJBwoFBgECBAP/xABOEAEAAQMDAQUEBgUIBgoBBQAAAQIDBAUGEQcIEiExQQkTUWEUFSIyUnEjQmKBkRYXJENygpKhM1Njc4OxNFSToqOys8HC8BgZRGTD0//EABsBAQACAwEBAAAAAAAAAAAAAAAGBwECBQQI/8QAMBEBAAECAwUHAwQDAAAAAAAAAAECBAMFEQYhMUFREhNxkaHB0RSBsRUWImEycuH/2gAMAwEAAhEDEQA/AO6+zw7DWF9U6d1S6gadRk38ji/omkZVMVUW6Ofs5FymfOZ86aZ9OJnzhY8/LGxrWHj2sexbps2LVEUW7dEcU0UxHEREekRD9QAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAH55GRaxLFy9fu0WbNuJqruXKopppj4zM+UPeqqKKZqqmIpiOZmfRA3tQdojJ37rOVtvQsmq1tvEuTbuXLczH0yuJ4mZ/YifKPXzHEzbNcHKcDvcTfM8I6z8dZZf6mdtfb+2r93C2vh/yiyqJ4nKrrm3jRPynzr/dxHzYM1ftl9TNRu1VY2fg6XRM+FGNhW6uI/O5FTBw20U3d7R5ldVTPezRHSnd68fVnHSO2X1M067TVk5+DqlET40ZOFbp5j87cUs59M+2vt/ct+1hbow/5O5Vc8RlUVzcxpn5z50fv5j5oNhoWm0eZWtUT3s1x0q3+vH1W6Y+Ray7Fu9Yu0XrNyIqouW6oqpqj4xMecP0QM7L/aIydhazi7b13Jqu7by7kW7d
...[truncated 27 chars]

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document is primarily a ribbon-fitting recipe for closed/self-intersecting shapes, but this section adds a separate workflow for matching wordmark fonts, including enumerating installed system fonts via shell commands. With no manifest available to justify broader typography or host-inspection behavior, this capability is not clearly supported by the file's stated purpose.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/render_overlay.py (reported line 71)May include surrounding context.

python
f'<body><img src="{svg.resolve().as_uri()}" width="{width}" height="{height}"></body></html>',
            encoding="utf-8",
        )
        subprocess.run(
            [
                chrome, "--headless=new", "--disable-gpu", "--hide-scrollbars",
                f"--screenshot={shot}", f"--window-size={width},{height}",

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The file includes Chinese-language content and later Chinese community text, but it does not indicate whether multilingual output is optional or user-selected. Under the policy, locale-specific language should be offered as a choice or clearly justified rather than imposed implicitly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file documents that the interactive showcase is published via GitHub Pages, and elsewhere it describes generating and publishing logo renderings, motion previews, and QA evidence. Because the skill operates on user-supplied logos and exports publishable artifacts, a user-facing warning about not publishing confidential or unlicensed brand assets is missing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document declares lang="en", and all visible instructional and descriptive text is English-only throughout the page. Under the policy rule for natural-language locale constraints, this can be flagged when a skill effectively forces a single language without any documented opt-in or alternative.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Most embedded examples in this file are self-contained animation demos, but the CueRecord Claude srcdoc contains extensive product-site content including navigation, download buttons, feature cards, product listings, brand strip, and footer. This diverges from the surrounding file’s demo-oriented intent and from the embedded animation framing, making the inline documentation/content contradict the actual narrow animation-comparison role of adjacent entries.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The meta title and description describe substantive app behavior such as on-device word tracking, teleprompter overlays, screen recording, camera overlay, and remote director controls. However, the actual embedded code in this file only builds UI/branding markup and animation logic for a logo hero, with no implementation of those stated application features.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This HTML page auto-replays animation groups when they scroll into view via an IntersectionObserver, which causes visible behavior without an explicit nearby warning to the user beyond a small footer note. For a markdown-or-code safety audit, this qualifies as a user-facing behavior that should be more clearly disclosed, especially because the page also programmatically clicks replay controls inside embedded frames.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code emits HTML with the language fixed to English, which is a natural-language locale decision applied to all generated output. The file does not offer a language option or explain why English is required, so it can violate locale-choice policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated document always sets <html lang="en">, which imposes a specific locale in the output. There is no user opt-in, configurability, or comment explaining why English is required for this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This code creates an output directory and writes SVG, HTML, PNG, and JSON artifacts, which is a file-modifying operation covered by the warning rule for code files. While the behavior is inferable from the script purpose, there is no confirmation prompt, inline comment/docstring near the write operations, or user-facing notice at execution time describing that files will be created or overwritten in the target directory.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/export_claude_videos.mjs:59