📦
Audit History
hairline-create - 1 audit
Audit version 1 Latest
Oct 4, 2026, 01:37 PM
Most static matches are benign JavaScript syntax, documentation, CSS, or intended local file operations. Automatic npm installation exposes the host to mutable dependencies and enabled lifecycle scripts, while browser inspection lacks network isolation. No evidence found of credential theft, malicious supplied figures, or audit-directed prompt injection.
11
Files scanned
1,859
Lines analyzed
8
Review items
0
False positives ignored
Confirmed security concerns (1)
Medium
Browser Inspection Lacks Network Isolation
The validator rejects literal API names, but does not establish a security boundary for JavaScript. Accepted figures execute without network blocking, so computed API access can reach external or local network services.
Source inspection shows regex-based API rejection and page navigation without request blocking. No evidence found of actual exfiltration or malicious supplied figures.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
High
Node.js child_process module
import { spawnSync } from "node:child_process";
The imported spawnSync is used at line 78 for automatic npm installation. Mutable dependency resolution and enabled lifecycle scripts expose the host to supply-chain execution.
High
Synchronous spawn
const run = spawnSync(win ? "npm.cmd" : "npm", ["install", "playwright-core@1", "--prefix", dir, "--
spawnSync automatically installs playwright-core@1 without disabling npm lifecycle scripts. A compromised dependency or existing cache manifest can execute host commands during installation.
Risk Factors
⚙️ External commands (50)
bench.html:83 bench.html:84 bench.html:91 bench.html:99 bench.html:100 bench.html:107 bench.html:122 bench.html:126 bench.html:127 bench.html:128 bench.html:129 build.mjs:25 build.mjs:3 build.mjs:14 build.mjs:18 build.mjs:19 build.mjs:22 build.mjs:25 build.mjs:39 examples/riffle.js:24 examples/riffle.js:57 examples/terrain.js:84 kernel.js:155 kernel.js:380 kernel.js:381 kernel.js:514 kernel.js:518 kernel.js:521 kernel.js:523 kernel.js:525 kernel.js:527 kernel.js:528 kernel.js:529 kernel.js:530 kernel.js:532 kernel.js:534 kernel.js:535 kernel.js:536 kernel.js:537 kernel.js:538 kernel.js:539 kernel.js:540 kernel.js:541 kernel.js:542 kernel.js:543 kernel.js:544 look.mjs:26 look.mjs:79 look.mjs:179 look.mjs:78
⚡ Contains scripts (9)
📁 Filesystem access (28)
build.mjs:8 build.mjs:16 build.mjs:17 build.mjs:38 build.mjs:40 build.mjs:25 look.md:22 look.md:22 look.mjs:27 look.mjs:76 look.mjs:172 look.mjs:177 look.mjs:179 validate.mjs:24 validate.mjs:163 validate.mjs:178 validate.mjs:215 validate.mjs:57 validate.mjs:73 validate.mjs:138 validate.mjs:145 validate.mjs:146 validate.mjs:151 validate.mjs:166 validate.mjs:180 validate.mjs:185 validate.mjs:24 validate.mjs:161
🔑 Env variables (1)
🌐 Network access (1)
Audited by: codex