vantajs
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
SKILL.mdfile contains instructions to loadthree.jsandvanta.jsfrom well-known CDNs (cdnjs.cloudflare.com and cdn.jsdelivr.net). These are standard industry practices for web development and are considered safe. - [COMMAND_EXECUTION]: No shell command execution or dynamic context injection patterns were found in the skill files.
- [DATA_EXFILTRATION]: No sensitive file access or unauthorized network operations were detected. The scripts in
demo/index.htmlare focused entirely on local Canvas rendering and UI manipulation. - [PROMPT_INJECTION]: The
demo/PROMPT.mdfile contains standard instruction-following prompts for recreation and remixing without any attempts to bypass safety filters or override agent behavior. - [REMOTE_CODE_EXECUTION]: There is no evidence of remote script execution (e.g., curl|bash) or unsafe dynamic code loading. The references to external scripts are for frontend library integration in a browser context.
Audit Metadata