marquee-loop
Warn
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADS
Full Analysis
- [OBFUSCATION]: The file
demo/index.htmlcontains a large Base64-encoded string (encodedHtml) that stores the complete HTML structure of the design demo. - [DYNAMIC_EXECUTION]: The skill utilizes
iframe.srcdocindemo/index.htmlto execute dynamically decoded content at runtime. It also implements awindow.postMessagelistener to receive asset data as Base64 strings, which are then converted into Blobs and Object URLs for interpolation into the document. - [EXTERNAL_DOWNLOADS]: The demo fetches design assets from Supabase (
hoirqrkdgbmvpwutwuwj.supabase.co) and loads runtime dependencies from well-known services including Cloudflare (cdnjs.cloudflare.com), Tailwind (cdn.tailwindcss.com), and Iconify (code.iconify.design).
Audit Metadata