scroll-native-css-timeline-page
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references an optional JavaScript polyfill (
scroll-timeline-polyfill) hosted oncdn.jsdelivr.net. This is a well-known content delivery network used for serving open-source libraries. The reference is documented neutrally as a browser compatibility fallback. - [REMOTE_CODE_EXECUTION]: While the skill provides JavaScript snippets in
EVAL.md, these are explicitly designed for manual execution by a developer within browser DevTools to audit CSS implementation correctness. They do not represent automated or hidden remote code execution. - [DATA_EXFILTRATION]: No patterns involving the access of sensitive files (e.g., SSH keys, credentials) or the exfiltration of data to external domains were found.
- [PROMPT_INJECTION]: The instructions are strictly technical and focused on CSS animation techniques. There are no attempts to override agent system prompts, bypass safety filters, or use adversarial role-play techniques.
- [OBFUSCATION]: The content is provided in clear text with no evidence of Base64 encoding, zero-width characters, homoglyphs, or other techniques used to hide malicious intent.
Audit Metadata