masked-reveal

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The JavaScript implementation for splitting text into words in SKILL.md includes a robust escapeHTML function to sanitize content before rendering, effectively preventing cross-site scripting (XSS) risks.
  • [SAFE]: The demo environment in demo/index.html employs a secure sandboxing strategy. The demonstration content is isolated within an iframe using sandbox="allow-scripts" and a restrictive Content Security Policy (CSP) that prevents unauthorized network requests and script execution.
  • [EXTERNAL_DOWNLOADS]: External library dependencies, including GSAP, ScrollTrigger, and Iconify, are sourced from well-known and reputable Content Delivery Networks (CDNs) as documented in demo/source.json and demo/index.html.
  • [SAFE]: The use of Base64 encoding for the demo HTML content in demo/index.html is used as a standard method for providing self-contained previews and does not contain hidden malicious instructions or commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:32 AM
Security Audit — agent-trust-hub — masked-reveal