html-code-review
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides explicit instructions to prevent Cross-Site Scripting (XSS) vulnerabilities in the generated HTML artifacts by mandating the use of textContent and createElement over innerHTML when handling variable data.
- [SAFE]: The skill operates on codebase content and pull request data, which represents an indirect prompt injection surface. The primary risk is mitigated by the structural and rendering focus of the skill, combined with the aforementioned XSS prevention measures.
- [SAFE]: External resource usage is restricted to Google Fonts, which is a well-known and generally safe service for font delivery. The skill explicitly discourages the use of external runtimes or CDNs.
Audit Metadata