gsap-scrolltrigger-storytelling
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's demo environment references and loads runtime libraries and assets from several well-known and trusted external services.
- Fetches the GSAP core and ScrollTrigger plugin from Cloudflare's CDN.
- Downloads iconography from the Iconify project.
- Loads styles and typography from Google Fonts.
- References media assets (images and video) hosted on Supabase storage.
- [SAFE]: The skill implementation follows security best practices for interactive demos.
- The demo landing page is embedded as a Base64-encoded string, which is decoded and executed within a sandboxed iframe. This is a standard packaging technique for this vendor to provide self-contained interactive previews.
- The demo loader implements a Content Security Policy (CSP) and utilizes the
sandboxattribute for theiframeelement to restrict the execution environment and prevent unauthorized actions. - Dependencies are linked to specific versions from reputable CDNs, minimizing supply chain risks.
Audit Metadata