split-layout-technical
Warn
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [OBFUSCATION]: The file
demo/index.htmlcontains a significant Base64-encoded string assigned to the variableencodedHtml. This string decodes to a full HTML document, effectively concealing the demo's structure and logic from static analysis tools. - [DYNAMIC_EXECUTION]: The skill utilizes dynamic content loading in
demo/index.html. It decodes theencodedHtmlstring usingatob()and injects the resulting content into a sandboxed iframe usingURL.createObjectURL()andsrcdoc. The skill also employs a message listener to dynamically process and decode Base64 asset data received from the parent window. - [EXTERNAL_DOWNLOADS]: The skill references several external assets and libraries from well-known services. It fetches image assets from Supabase storage and loads standard web development libraries including Tailwind CSS, GSAP, and Iconify from their respective official CDNs. These downloads are consistent with the skill's primary purpose and originate from recognized, reputable sources.
Audit Metadata