htmx

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a high-quality documentation suite for the htmx library (version 2.0.10). The information is accurate, well-structured, and emphasizes security best practices such as CSRF protection, XSS prevention through sanitization, and Content Security Policy (CSP) implementation.
  • [EXTERNAL_DOWNLOADS]: The skill mentions external sources for the htmx library (unpkg.com, npmjs.com) and community extensions (idiomorph). These references are standard for web development libraries and target well-known, trusted services for their intended purpose, which is safe according to the analysis guidelines.
  • [COMMAND_EXECUTION]: Example command-line snippets for package managers (npm, pip) are provided for installation purposes. These are standard developer instructions and do not represent a security risk.
  • [DATA_EXFIILLTRATION]: No data exfiltration patterns were found. The documentation correctly identifies how to manage sensitive data by disabling history caching for specific pages using hx-history="false".
  • [PROMPT_INJECTION]: The skill does not contain any instructions aimed at overriding agent behavior or bypassing safety filters. It remains strictly focused on technical documentation.
  • [NO_CODE]: The skill predominantly consists of markdown documentation. The included Python script (scripts/check-updates.py) is a maintenance tool that performs benign version and file integrity checks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:30 AM
Security Audit — agent-trust-hub — htmx