nested-container-frames

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [OBFUSCATION]: The file demo/index.html contains a large Base64-encoded string (encodedHtml) that decodes to the HTML source code for the skill's visual demo. This is a standard packaging technique for the provider's demo environment.
  • [DYNAMIC_EXECUTION]: The demo loader in demo/index.html utilizes srcdoc, atob(), and URL.createObjectURL() to dynamically assemble and execute the design preview. This behavior is confined within an iframe using sandbox="allow-scripts" and a restrictive Content Security Policy (CSP) that prevents external network access except for specific trusted font providers.
  • [EXTERNAL_DOWNLOADS]: The demo payload references external typography resources from Google Fonts and Fontshare. These are well-known services and do not pose a security risk in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:33 AM
Security Audit — agent-trust-hub — nested-container-frames