gooey-blob-system

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [OBFUSCATION]: The demo/index.html file packages the demo implementation within a large Base64-encoded string (encodedHtml). Analysis of the decoded content confirms it contains legitimate HTML, CSS, and JavaScript for SVG filter animations and GSAP-based movement. This is a standard delivery mechanism for the sandboxed demo environment.\n- [EXTERNAL_DOWNLOADS]: The demo references external runtime scripts from trusted and well-known services, including GSAP via Cloudflare's CDN and Tailwind CSS. These dependencies are used for styling and interaction logic consistent with the skill's visual design purpose.\n- [INDIRECT_PROMPT_INJECTION]: The skill uses external design references (e.g., from neuform.ai) within its prompts and workflow to provide context for the agent.\n
  • Ingestion points: External design reference URL in demo/PROMPT.md.\n
  • Boundary markers: Absent.\n
  • Capability inventory: SVG filter definitions, CSS animations, and DOM manipulation.\n
  • Sanitization: Not applicable as the ingested content is used as a static visual reference rather than being dynamically executed or parsed for instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:32 AM
Security Audit — agent-trust-hub — gooey-blob-system