glass-dark-mode-clock
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references Google Fonts (
fonts.googleapis.com) and fetches icons from Iconify via a local runtime script. These are standard, well-known services used for UI development. - [OBFUSCATION]: The file
demo/index.htmlcontains a large Base64-encoded string representing the demo's HTML content. Analysis of the decoded content shows it is a legitimate UI template for the 'Alert Interface' design, containing WebGL and Canvas animations. The encoding is used for bundling the demo into a single file rather than concealing malicious intent. - [COMMAND_EXECUTION]: No shell commands or arbitrary code execution patterns were detected in the skill instructions or scripts.
- [DATA_EXFILTRATION]: No patterns for accessing sensitive files (e.g.,
.env, SSH keys) or exfiltrating data to external servers were found. The demo uses a restrictive Content Security Policy (CSP) that blocks unauthorized network connections. - [PROMPT_INJECTION]: The skill instructions are focused entirely on visual design patterns and implementation guidance. There are no attempts to override agent safety filters or manipulate the underlying AI model's behavior.
Audit Metadata