framed-grid-layout

Warn

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADS
Full Analysis
  • [OBFUSCATION]: The file demo/index.html contains a large Base64-encoded payload in the encodedHtml variable representing an entire HTML document. This technique is used to bundle demo content but obscures the code from static inspection.- [EXTERNAL_DOWNLOADS]: The skill references and fetches resources from well-known services:
  • https://fonts.googleapis.com and https://fonts.gstatic.com for typography.
  • https://cdn.tailwindcss.com/ for styling logic.
  • https://code.iconify.design for icon assets.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external UI references and metadata from the vendor's platform. * Ingestion points: demo/source.json and design references in demo/PROMPT.md. * Boundary markers: Not present. * Capability inventory: Restricted to CSS and HTML rendering within a sandboxed environment. * Sanitization: The demo uses an iframe with sandbox="allow-scripts" and a strict Content Security Policy (CSP).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 16, 2026, 07:33 AM
Security Audit — agent-trust-hub — framed-grid-layout