container-lines
Warn
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [OBFUSCATION]: The file
demo/index.htmlcontains a large Base64-encoded string (encodedHtml) representing an entire HTML design demo. This encoding obscures the content from static analysis tools. - [DYNAMIC_EXECUTION]: The skill uses JavaScript in
demo/index.htmlto decode theencodedHtmlstring at runtime and inject it into an iframe usingsrcdoc. It also dynamically converts Base64 asset data into Blobs usingURL.createObjectURL, which involves runtime assembly and execution of content. - [INDIRECT_PROMPT_INJECTION]: The
demo/PROMPT.mdfile contains instructions for the agent to visit and analyze an external URL (https://neuform.ai/...) to match its design fidelity. This exposes the agent to potential malicious instructions hidden in the remote content. - Ingestion points: The agent is directed to visit the design URL via
demo/PROMPT.md. - Boundary markers: Absent; no instructions are provided to ignore embedded commands.
- Capability inventory: The agent is tasked with HTML/CSS code generation; no sensitive system tools are directly invoked.
- Sanitization: Absent; external content is used directly as a reference for code generation.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill's demo configuration in
demo/source.jsonand the decoded HTML reference external runtime libraries and assets from sources like Google Fonts, Cloudflare (GSAP), and Supabase. These are well-known services and the references are consistent with the skill's purpose.
Audit Metadata