high-contrast-skeuomorphic-clean

Warn

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The file demo/index.html contains a very large Base64-encoded string (encodedHtml) that stores the entire HTML, CSS, and JavaScript payload for the design demo. Hiding executable logic in this manner is a common technique for bypassing static analysis.
  • [DYNAMIC_EXECUTION]: The demo environment in demo/index.html decodes the Base64 payload at runtime and injects it into a sandboxed iframe using the srcdoc attribute. It also dynamically generates Blob objects and Object URLs for media assets received via postMessage.
  • [EXTERNAL_DOWNLOADS]: The skill fetches several runtime dependencies from well-known services. These are identified in demo/source.json and loaded via relative paths in demo/index.html that resolve to external CDN sources:
  • GSAP library from cdnjs.cloudflare.com.
  • Iconify components from code.iconify.design.
  • Tailwind CSS from cdn.tailwindcss.com.
  • Google Fonts from fonts.googleapis.com and fonts.gstatic.com.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to generate complex HTML/CSS based on user prompts and design guidelines in SKILL.md.
  • Ingestion points: User instructions processed via demo/PROMPT.md.
  • Boundary markers: None identified to separate instructions from untrusted data.
  • Capability inventory: Generation and execution of HTML and JavaScript via a browser-based sandboxed environment.
  • Sanitization: While strict Content Security Policies (CSP) are applied to the demo iframe, the underlying mechanism for interpolating user-controlled data into generated templates lacks explicit sanitization, posing a risk of indirect prompt injection.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 16, 2026, 07:32 AM
Security Audit — agent-trust-hub — high-contrast-skeuomorphic-clean