skills/ericrisco/rsc-harness/htmx/Gen Agent Trust Hub

htmx

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive guidance on building hypermedia-driven UIs using htmx. It includes valid references to official content and well-known services.
  • [EXTERNAL_DOWNLOADS]: The skill references the htmx library via unpkg.com, which is a standard and well-known CDN for serving official package distributions. Documentation neutrally describes this as the recommended method for including the library.
  • [COMMAND_EXECUTION]: A utility script scripts/verify.sh is provided. Analysis shows it is a read-only static linter that uses grep and sed to detect common syntax errors or potential XSS surfaces (like the use of | safe filters) in local template files. It does not perform network operations or access sensitive system files.
  • [PROMPT_INJECTION]: No prompt injection or behavior override patterns were detected. The instructions follow standard agent skill formatting and focus on technical implementation rules.
  • [DATA_EXFILTRATION]: No data exfiltration patterns were found. The skill explicitly instructs users to maintain CSRF protections and use same-origin requests (selfRequestsOnly) to prevent cross-origin data leaks.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials or instructions to store secrets insecurely were found. The skill correctly advises using environment-specific CSRF tokens via standard template variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — htmx