split-layout-technical

Warn

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [OBFUSCATION]: The file demo/index.html contains a significant Base64-encoded string assigned to the variable encodedHtml. This string decodes to a full HTML document, effectively concealing the demo's structure and logic from static analysis tools.
  • [DYNAMIC_EXECUTION]: The skill utilizes dynamic content loading in demo/index.html. It decodes the encodedHtml string using atob() and injects the resulting content into a sandboxed iframe using URL.createObjectURL() and srcdoc. The skill also employs a message listener to dynamically process and decode Base64 asset data received from the parent window.
  • [EXTERNAL_DOWNLOADS]: The skill references several external assets and libraries from well-known services. It fetches image assets from Supabase storage and loads standard web development libraries including Tailwind CSS, GSAP, and Iconify from their respective official CDNs. These downloads are consistent with the skill's primary purpose and originate from recognized, reputable sources.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 16, 2026, 07:33 AM
Security Audit — agent-trust-hub — split-layout-technical