corner-diagonals
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [OBFUSCATION]: The file
demo/index.htmlcontains a Base64-encoded HTML blob used to render a sandboxed design preview. Decoding and inspecting this content reveals standard HTML, CSS, and JavaScript for a landing page, including WebGL shaders and GSAP animations, with no malicious intent detected. - [EXTERNAL_DOWNLOADS]: The skill's metadata and demo reference several well-known CDN services, including Cloudflare (cdnjs), Google Fonts, and Iconify. These are used to load established libraries like Three.js, GSAP, and Tailwind CSS. All identified external resources originate from trusted or well-known service providers.
- [COMMAND_EXECUTION]: The skill focuses on CSS styling and HTML structure. There are no shell commands, subprocess calls, or system-level operations present in the instructions or scripts.
- [INDIRECT_PROMPT_INJECTION]: The demo environment includes a mechanism for ingesting assets via
postMessagewithin a sandboxediframe. While this constitutes a data ingestion surface, the implementation is confined to the design preview context and lacks access to sensitive capabilities, posing no significant security risk.
Audit Metadata