marquee-loop

Warn

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADS
Full Analysis
  • [OBFUSCATION]: The file demo/index.html contains a large Base64-encoded string (encodedHtml) that stores the complete HTML structure of the design demo.
  • [DYNAMIC_EXECUTION]: The skill utilizes iframe.srcdoc in demo/index.html to execute dynamically decoded content at runtime. It also implements a window.postMessage listener to receive asset data as Base64 strings, which are then converted into Blobs and Object URLs for interpolation into the document.
  • [EXTERNAL_DOWNLOADS]: The demo fetches design assets from Supabase (hoirqrkdgbmvpwutwuwj.supabase.co) and loads runtime dependencies from well-known services including Cloudflare (cdnjs.cloudflare.com), Tailwind (cdn.tailwindcss.com), and Iconify (code.iconify.design).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 16, 2026, 07:33 AM
Security Audit — agent-trust-hub — marquee-loop