background-grid-webgl
Warn
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [OBFUSCATION]: The file
demo/index.htmlcontains a large Base64-encoded string (encodedHtml) which obfuscates the primary HTML and JavaScript code for the demo design. - [DYNAMIC_EXECUTION]: The
demo/index.htmlscript decodes theencodedHtmlstring and injects it into an iframe'ssrcdocattribute, resulting in the runtime execution of the decoded scripts. This pattern represents dynamic code generation and execution from an encoded source. - [REMOTE_CODE_EXECUTION]: The demo environment configuration in
demo/source.jsonand the content within the decoded demo HTML reference external runtime scripts from well-known services, specifically Tailwind CSS and Iconify. These are executed to support the demo interface.
Audit Metadata