Skills hairline-create Audit History
📦

Audit History

hairline-create - 1 audit

Oct 4, 2026, 01:37 PM

Most static matches are benign JavaScript syntax, documentation, CSS, or intended local file operations. Automatic npm installation exposes the host to mutable dependencies and enabled lifecycle scripts, while browser inspection lacks network isolation. No evidence found of credential theft, malicious supplied figures, or audit-directed prompt injection.

11
Files scanned
1,859
Lines analyzed
8
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Browser Inspection Lacks Network Isolation
The validator rejects literal API names, but does not establish a security boundary for JavaScript. Accepted figures execute without network blocking, so computed API access can reach external or local network services.
Source inspection shows regex-based API rejection and page navigation without request blocking. No evidence found of actual exfiltration or malicious supplied figures.
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
Node.js child_process module
import { spawnSync } from "node:child_process";
The imported spawnSync is used at line 78 for automatic npm installation. Mutable dependency resolution and enabled lifecycle scripts expose the host to supply-chain execution.
High
Synchronous spawn
const run = spawnSync(win ? "npm.cmd" : "npm", ["install", "playwright-core@1", "--prefix", dir, "--
spawnSync automatically installs playwright-core@1 without disabling npm lifecycle scripts. A compromised dependency or existing cache manifest can execute host commands during installation.
Audited by: codex