skills/devinilabs/pro-skill/gsap/Gen Agent Trust Hub

gsap

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references several external resources, all of which originate from trusted or well-known services.
  • Fetches fonts from Google Fonts (fonts.googleapis.com, fonts.gstatic.com).
  • References official GSAP documentation on gsap.com.
  • The demo includes runtime scripts originating from well-known CDNs like Cloudflare (cdnjs.cloudflare.com), Iconify (code.iconify.design), and Tailwind CSS (cdn.tailwindcss.com).
  • Static assets are hosted on Supabase, which is a well-known infrastructure provider.
  • [OBFUSCATION]: The file demo/index.html contains a large Base64-encoded string (encodedHtml).
  • Analysis confirms this string decodes to a standard HTML document for the 'Aura' interaction demo.
  • The use of srcdoc and postMessage for asset loading is a common pattern for creating isolated, self-contained web previews and does not indicate malicious intent in this context.
  • [COMMAND_EXECUTION]: No direct command execution or shell scripts were found. The skill focuses entirely on client-side web animations and UI design patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:32 AM
Security Audit — agent-trust-hub — gsap