nested-container-frames
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [OBFUSCATION]: The file
demo/index.htmlcontains a large Base64-encoded string (encodedHtml) that decodes to the HTML source code for the skill's visual demo. This is a standard packaging technique for the provider's demo environment. - [DYNAMIC_EXECUTION]: The demo loader in
demo/index.htmlutilizessrcdoc,atob(), andURL.createObjectURL()to dynamically assemble and execute the design preview. This behavior is confined within an iframe usingsandbox="allow-scripts"and a restrictive Content Security Policy (CSP) that prevents external network access except for specific trusted font providers. - [EXTERNAL_DOWNLOADS]: The demo payload references external typography resources from Google Fonts and Fontshare. These are well-known services and do not pose a security risk in this context.
Audit Metadata