gooey-blob-system
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [OBFUSCATION]: The
demo/index.htmlfile packages the demo implementation within a large Base64-encoded string (encodedHtml). Analysis of the decoded content confirms it contains legitimate HTML, CSS, and JavaScript for SVG filter animations and GSAP-based movement. This is a standard delivery mechanism for the sandboxed demo environment.\n- [EXTERNAL_DOWNLOADS]: The demo references external runtime scripts from trusted and well-known services, including GSAP via Cloudflare's CDN and Tailwind CSS. These dependencies are used for styling and interaction logic consistent with the skill's visual design purpose.\n- [INDIRECT_PROMPT_INJECTION]: The skill uses external design references (e.g., fromneuform.ai) within its prompts and workflow to provide context for the agent.\n - Ingestion points: External design reference URL in
demo/PROMPT.md.\n - Boundary markers: Absent.\n
- Capability inventory: SVG filter definitions, CSS animations, and DOM manipulation.\n
- Sanitization: Not applicable as the ingested content is used as a static visual reference rather than being dynamically executed or parsed for instructions.
Audit Metadata