Caveat verdict

code2animation

88
🟢 Trusted
No high-risk patterns surfaced by the deep scan — automated capability review, not behavioral proof.

Video editing skill that creates code-driven animations using Microsoft Edge TTS and Puppeteer/FFmpeg for rendering; all capabilities align with its stated media generation purpose.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

0
security
80
transparency
80
maintenance

Findings (9)

Pattern match critical

<script> tag in markdown — potential code injection

SKILL.md · code · <script>

Pattern match high

References sudo — requests elevated privileges

README.md · code · sudo

Pattern match high

apt-get install — installs system packages

README.md · code · apt-get install

Pattern match medium

Long base64 string (100+ chars) — likely obfuscated payload

package.json · prose · downgraded · ad27a79641b49c3e481a16a805baa71817a04bbe06a38d17e60e2eaee83f6a146c6a688125f5792e

Pattern match medium

References child_process — can spawn system processes

scripts/compress.js · prose · downgraded · child_process

Pattern match medium

Downloads executables from external URLs

scripts/README.md · prose · downgraded · Download from https://

Pattern match medium

Dynamic import() — loads module at runtime

scripts/render.ts · prose · downgraded · import('

Pattern match medium

Uses spawn() — can execute external programs

scripts/render.ts · prose · downgraded · spawn(

Pattern match medium

setuid — privilege escalation mechanism

scripts/render.ts · prose · downgraded · setuid

Why the tier is capped

Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.

Permissions & capabilities

No declared permissions — minimal attack surface.

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API