html-interactive-playground

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill promotes secure development practices by explicitly instructing the agent to use textContent and document.createElement instead of innerHTML to prevent XSS vulnerabilities when generating dynamic HTML content.
  • [COMMAND_EXECUTION]: The skill requires the agent to call the html-skills-listen tool to set up a local receiver. This is a legitimate and documented function of the skill for establishing a two-way communication channel between the agent and the generated interactive artifact.
  • [DATA_EXFILTRATION]: Data transfer is restricted to localhost (127.0.0.1) or the system clipboard for returning values from the HTML artifact to the agent. No communication with untrusted external domains is established.
  • [EXTERNAL_DOWNLOADS]: The skill permits the use of Google Fonts, which is a well-known and trusted service, while explicitly discouraging other external CDN or npm dependencies to ensure artifacts remain self-contained.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 04:18 AM
Security Audit — agent-trust-hub — html-interactive-playground