create-html-report

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches resources such as CSS, JavaScript, and fonts from vendor-owned infrastructure (alfonsograziano.it) and well-known content delivery networks including Google Fonts, JSDelivr, ESM.sh, and Cloudflare.
  • [COMMAND_EXECUTION]: Instructions direct the agent to run a local validation script (scripts/check.mjs) using Node.js. This script launches a browser via Puppeteer to verify report layout and capture diagnostic screenshots.
  • [DYNAMIC_EXECUTION]: The toolkit uses a Function constructor in its browser-side logic (assets/report.js) to evaluate mathematical formulas for interactive 'what-if' calculators defined within the generated HTML.
  • [DYNAMIC_EXECUTION]: Visualization libraries such as Chart.js, Mermaid, and Excalidraw are dynamically loaded from trusted remote CDNs at runtime only when a report utilizes those specific features.
  • [DYNAMIC_EXECUTION]: The checker utility uses Puppeteer's page.evaluate method to execute diagnostic scripts within the rendered browser environment to check for layout overflows and console errors.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 08:26 AM
Security Audit — agent-trust-hub — create-html-report