number-details
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The demo loader in
demo/index.htmlcontains a large Base64-encoded string (encodedHtml) which decodes to the full HTML structure and initialization logic for the design demo. - [DYNAMIC_EXECUTION]: The
demo/index.htmlscript decodes bundled HTML at runtime and injects it into a sandboxed iframe using thesrcdocattribute. It also dynamically resolves and injects paths for runtime dependencies. - [EXTERNAL_DOWNLOADS]: The skill fetches several runtime scripts and fonts from well-known and trusted services, including Google Fonts, Cloudflare (cdnjs), and the Iconify CDN. These are documented in
demo/source.jsonas verified dependencies. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted 'Product brief' and 'Reference snapshot' data from
demo/PROMPT.mdto generate code. 1. Ingestion points:demo/PROMPT.md. 2. Boundary markers: Absent. 3. Capability inventory: Full HTML/JavaScript code generation. 4. Sanitization: Absent.
Audit Metadata