css-border-gradient
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [OBFUSCATION]: The
demo/index.htmlfile includes a large Base64-encoded string (encodedHtml) that contains the full source for the design demo. This content is decoded at runtime to populate a sandboxed iframe. - [EXTERNAL_DOWNLOADS]: The demo environment fetches runtime libraries (Tailwind CSS, GSAP, ScrollTrigger, and Iconify) from well-known services such as
cdn.tailwindcss.com,cdnjs.cloudflare.com, andcode.iconify.design. - [EXTERNAL_DOWNLOADS]: Product and background images for the demo are retrieved from Supabase (
hoirqrkdgbmvpwutwuwj.supabase.co), which is a recognized cloud service provider. - [DYNAMIC_EXECUTION]: The skill uses
srcdocto render dynamically decoded HTML and employswindow.postMessagefor injecting asset URLs into the sandboxed iframe. The bundled code usesatobfor decoding content. - [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection as it instructions the agent to ingest external design references and product briefs from
demo/PROMPT.mdto generate UI code. - Ingestion points:
demo/PROMPT.md(reference URLs and design brief content). - Boundary markers: Not present.
- Capability inventory: The skill provides CSS/HTML templates; no subprocess, network write, or file system write capabilities are present in the skill code.
- Sanitization: No sanitization or filtering of external design content is performed by the skill instructions.
Audit Metadata