html-comparison-matrix
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified in the skill's instructions or logic.
- [DATA_EXFILTRATION]: The skill implements a submission pipeline that sends data back to the agent via a local ephemeral port or the clipboard. This behavior is documented, intended for the skill's functionality, and targets localhost (127.0.0.1), which is a whitelisted environment.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied candidates and criteria. It mitigates potential injection or cross-site scripting (XSS) risks by mandating the use of
textContentanddocument.createElementwhile explicitly prohibiting the use ofinnerHTMLwith variable data. - [EXTERNAL_DOWNLOADS]: The skill allows the use of Google Fonts via
<link>tags, which is a well-known and trusted service for web artifacts. - [COMMAND_EXECUTION]: The skill instructs the agent to run a specific helper tool (
html-skills:html-skills-listen) to set up a local receiver. This is a controlled tool invocation within the agent's environment and is necessary for the skill's interactive features.
Audit Metadata