gsap
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references several external resources, all of which originate from trusted or well-known services.
- Fetches fonts from Google Fonts (
fonts.googleapis.com,fonts.gstatic.com). - References official GSAP documentation on
gsap.com. - The demo includes runtime scripts originating from well-known CDNs like Cloudflare (
cdnjs.cloudflare.com), Iconify (code.iconify.design), and Tailwind CSS (cdn.tailwindcss.com). - Static assets are hosted on Supabase, which is a well-known infrastructure provider.
- [OBFUSCATION]: The file
demo/index.htmlcontains a large Base64-encoded string (encodedHtml). - Analysis confirms this string decodes to a standard HTML document for the 'Aura' interaction demo.
- The use of
srcdocandpostMessagefor asset loading is a common pattern for creating isolated, self-contained web previews and does not indicate malicious intent in this context. - [COMMAND_EXECUTION]: No direct command execution or shell scripts were found. The skill focuses entirely on client-side web animations and UI design patterns.
Audit Metadata