create-html-report
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches resources such as CSS, JavaScript, and fonts from vendor-owned infrastructure (alfonsograziano.it) and well-known content delivery networks including Google Fonts, JSDelivr, ESM.sh, and Cloudflare.
- [COMMAND_EXECUTION]: Instructions direct the agent to run a local validation script (scripts/check.mjs) using Node.js. This script launches a browser via Puppeteer to verify report layout and capture diagnostic screenshots.
- [DYNAMIC_EXECUTION]: The toolkit uses a Function constructor in its browser-side logic (assets/report.js) to evaluate mathematical formulas for interactive 'what-if' calculators defined within the generated HTML.
- [DYNAMIC_EXECUTION]: Visualization libraries such as Chart.js, Mermaid, and Excalidraw are dynamically loaded from trusted remote CDNs at runtime only when a report utilizes those specific features.
- [DYNAMIC_EXECUTION]: The checker utility uses Puppeteer's page.evaluate method to execute diagnostic scripts within the rendered browser environment to check for layout overflows and console errors.
Audit Metadata