html-svg-diagrams
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill demonstrates strong defensive design by mandating that the agent use
textContentandcreateElementfor building the DOM, which effectively mitigates XSS risks when rendering user-provided technical concepts. Furthermore, the skill explicitly prohibits the use of persistent browser storage (localStorage,IndexedDB) and restricts external resource loading to well-known, trusted font services, minimizing the potential attack surface. No evidence of prompt injection, unauthorized network operations, or persistence mechanisms was found.
Audit Metadata