html-brainstorm-grid
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [SAFE]: The skill provides instructions for generating secure HTML artifacts. It explicitly mandates the use of safe DOM manipulation methods such as 'textContent' and 'document.createElement' while forbidding 'innerHTML' to prevent Cross-Site Scripting (XSS) vulnerabilities.
- [EXTERNAL_DOWNLOADS]: The skill permits the use of Google Fonts via '' tags, which is a trusted and standard service for web typography. No other external or untrusted dependencies are requested or used.
- [DATA_EXFILTRATION]: The skill implements a submission mechanism to return user interactions back to the agent. This is achieved through a local ephemeral server (via the 'html-skills-listen' helper) or the system clipboard, which is the intended and documented behavior for this interactive plugin.
Audit Metadata