html-interactive-playground
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill promotes secure development practices by explicitly instructing the agent to use
textContentanddocument.createElementinstead ofinnerHTMLto prevent XSS vulnerabilities when generating dynamic HTML content. - [COMMAND_EXECUTION]: The skill requires the agent to call the
html-skills-listentool to set up a local receiver. This is a legitimate and documented function of the skill for establishing a two-way communication channel between the agent and the generated interactive artifact. - [DATA_EXFILTRATION]: Data transfer is restricted to
localhost(127.0.0.1) or the system clipboard for returning values from the HTML artifact to the agent. No communication with untrusted external domains is established. - [EXTERNAL_DOWNLOADS]: The skill permits the use of Google Fonts, which is a well-known and trusted service, while explicitly discouraging other external CDN or npm dependencies to ensure artifacts remain self-contained.
Audit Metadata