htmx
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive guidance on building hypermedia-driven UIs using htmx. It includes valid references to official content and well-known services.
- [EXTERNAL_DOWNLOADS]: The skill references the htmx library via unpkg.com, which is a standard and well-known CDN for serving official package distributions. Documentation neutrally describes this as the recommended method for including the library.
- [COMMAND_EXECUTION]: A utility script
scripts/verify.shis provided. Analysis shows it is a read-only static linter that uses grep and sed to detect common syntax errors or potential XSS surfaces (like the use of| safefilters) in local template files. It does not perform network operations or access sensitive system files. - [PROMPT_INJECTION]: No prompt injection or behavior override patterns were detected. The instructions follow standard agent skill formatting and focus on technical implementation rules.
- [DATA_EXFILTRATION]: No data exfiltration patterns were found. The skill explicitly instructs users to maintain CSRF protections and use same-origin requests (selfRequestsOnly) to prevent cross-origin data leaks.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials or instructions to store secrets insecurely were found. The skill correctly advises using environment-specific CSRF tokens via standard template variables.
Audit Metadata