editorial-tech

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's demo component references external assets and libraries from trusted organizations and well-known services. It uses Supabase for image hosting and reputable CDNs (Cloudflare, Tailwind, Iconify) for standard design libraries. These are established resources for high-end web development and are considered safe under the trust-scope rules.
  • [DYNAMIC_EXECUTION]: The demo environment uses a sandboxed iframe with a Base64-encoded HTML template to provide interactive previews. This is a common and secure method for isolating UI demos. The implementation includes a Content Security Policy (CSP) and appropriate iframe sandboxing to ensure the code remains within its intended scope.
  • [DATA_EXFILTRATION]: Analysis of the skill's network operations shows no evidence of unauthorized data collection. Network requests are limited to fetching local demo assets and public design dependencies from recognized providers.
  • [PROMPT_INJECTION]: The instructional content in SKILL.md and the example prompts in PROMPT.md are strictly focused on layout, typography, and aesthetic principles. There are no attempts to override agent behavior, bypass safety filters, or extract system prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:32 AM
Security Audit — agent-trust-hub — editorial-tech