high-contrast-skeuomorphic-clean
Warn
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The file
demo/index.htmlcontains a very large Base64-encoded string (encodedHtml) that stores the entire HTML, CSS, and JavaScript payload for the design demo. Hiding executable logic in this manner is a common technique for bypassing static analysis. - [DYNAMIC_EXECUTION]: The demo environment in
demo/index.htmldecodes the Base64 payload at runtime and injects it into a sandboxed iframe using thesrcdocattribute. It also dynamically generates Blob objects and Object URLs for media assets received viapostMessage. - [EXTERNAL_DOWNLOADS]: The skill fetches several runtime dependencies from well-known services. These are identified in
demo/source.jsonand loaded via relative paths indemo/index.htmlthat resolve to external CDN sources: - GSAP library from
cdnjs.cloudflare.com. - Iconify components from
code.iconify.design. - Tailwind CSS from
cdn.tailwindcss.com. - Google Fonts from
fonts.googleapis.comandfonts.gstatic.com. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to generate complex HTML/CSS based on user prompts and design guidelines in
SKILL.md. - Ingestion points: User instructions processed via
demo/PROMPT.md. - Boundary markers: None identified to separate instructions from untrusted data.
- Capability inventory: Generation and execution of HTML and JavaScript via a browser-based sandboxed environment.
- Sanitization: While strict Content Security Policies (CSP) are applied to the demo iframe, the underlying mechanism for interpolating user-controlled data into generated templates lacks explicit sanitization, posing a risk of indirect prompt injection.
Audit Metadata