html-throwaway-editor

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to generate interactive HTML and JavaScript files. It mandates security best practices to prevent Cross-Site Scripting (XSS) by explicitly forbidding the use of innerHTML with variable or untrusted data, requiring safe alternatives like textContent and createElement.
  • [EXTERNAL_DOWNLOADS]: The instructions permit loading Google Fonts but strictly prohibit other Content Delivery Networks (CDNs) or external NPM packages. This ensures that the generated artifacts remain self-contained and minimizes the external attack surface.
  • [DATA_EXFILTRATION]: The skill implements a submission mechanism to return user-edited data to the agent. This process utilizes a local loopback server (127.0.0.1) or the system clipboard, which are standard patterns for local-first agent tools and do not involve untrusted remote endpoints.
  • [SAFE]: The skill shows high security maturity by incorporating explicit instructions for the agent to avoid common web security pitfalls such as persistent browser storage and unsafe string-based DOM manipulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 04:18 AM
Security Audit — agent-trust-hub — html-throwaway-editor