light-mode-paper-technical
Fail
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The file
demo/index.htmlcontains a large Base64-encoded string assigned to the variableencodedHtml. This string decodes to a full HTML document including inline scripts and styles, effectively hiding the demo's implementation details from static analysis. - [DYNAMIC_EXECUTION]: The script in
demo/index.htmldecodes theencodedHtmlpayload and injects it into an iframe using thesrcdocattribute. It also dynamically creates and revokes Blob URLs for local assets, which are then injected into the DOM of the sandboxed iframe. - [REMOTE_CODE_EXECUTION]: The decoded payload in
demo/index.htmlreferences external runtime dependencies and stylesheets, including Google Fonts and Fontshare. According todemo/source.json, it also relies on external runtime scripts for Tailwind CSS and Iconify. While these originate from well-known services, the execution occurs within the context of the generated demo. - [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection by instructing the agent to ingest and replicate external design references from
neuform.aibased on user-provided or prompt-defined URLs. - Ingestion points: External URLs provided in
demo/PROMPT.mdand metadata indemo/source.json. - Boundary markers: None identified in the provided files.
- Capability inventory: The skill is designed to generate HTML/CSS content; standard file-write and agent-controlled browser capabilities would be used to fulfill the prompt.
- Sanitization: No explicit sanitization or validation of the ingested design reference content is mentioned.
Recommendations
- AI detected serious security threats
Audit Metadata