light-mode-paper-technical

Fail

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The file demo/index.html contains a large Base64-encoded string assigned to the variable encodedHtml. This string decodes to a full HTML document including inline scripts and styles, effectively hiding the demo's implementation details from static analysis.
  • [DYNAMIC_EXECUTION]: The script in demo/index.html decodes the encodedHtml payload and injects it into an iframe using the srcdoc attribute. It also dynamically creates and revokes Blob URLs for local assets, which are then injected into the DOM of the sandboxed iframe.
  • [REMOTE_CODE_EXECUTION]: The decoded payload in demo/index.html references external runtime dependencies and stylesheets, including Google Fonts and Fontshare. According to demo/source.json, it also relies on external runtime scripts for Tailwind CSS and Iconify. While these originate from well-known services, the execution occurs within the context of the generated demo.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection by instructing the agent to ingest and replicate external design references from neuform.ai based on user-provided or prompt-defined URLs.
  • Ingestion points: External URLs provided in demo/PROMPT.md and metadata in demo/source.json.
  • Boundary markers: None identified in the provided files.
  • Capability inventory: The skill is designed to generate HTML/CSS content; standard file-write and agent-controlled browser capabilities would be used to fulfill the prompt.
  • Sanitization: No explicit sanitization or validation of the ingested design reference content is mentioned.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 16, 2026, 07:33 AM
Security Audit — agent-trust-hub — light-mode-paper-technical