gsap-scrolltrigger-storytelling

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's demo environment references and loads runtime libraries and assets from several well-known and trusted external services.
  • Fetches the GSAP core and ScrollTrigger plugin from Cloudflare's CDN.
  • Downloads iconography from the Iconify project.
  • Loads styles and typography from Google Fonts.
  • References media assets (images and video) hosted on Supabase storage.
  • [SAFE]: The skill implementation follows security best practices for interactive demos.
  • The demo landing page is embedded as a Base64-encoded string, which is decoded and executed within a sandboxed iframe. This is a standard packaging technique for this vendor to provide self-contained interactive previews.
  • The demo loader implements a Content Security Policy (CSP) and utilizes the sandbox attribute for the iframe element to restrict the execution environment and prevent unauthorized actions.
  • Dependencies are linked to specific versions from reputable CDNs, minimizing supply chain risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:32 AM
Security Audit — agent-trust-hub — gsap-scrolltrigger-storytelling