html-throwaway-editor
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to generate interactive HTML and JavaScript files. It mandates security best practices to prevent Cross-Site Scripting (XSS) by explicitly forbidding the use of
innerHTMLwith variable or untrusted data, requiring safe alternatives liketextContentandcreateElement. - [EXTERNAL_DOWNLOADS]: The instructions permit loading Google Fonts but strictly prohibit other Content Delivery Networks (CDNs) or external NPM packages. This ensures that the generated artifacts remain self-contained and minimizes the external attack surface.
- [DATA_EXFILTRATION]: The skill implements a submission mechanism to return user-edited data to the agent. This process utilizes a local loopback server (127.0.0.1) or the system clipboard, which are standard patterns for local-first agent tools and do not involve untrusted remote endpoints.
- [SAFE]: The skill shows high security maturity by incorporating explicit instructions for the agent to avoid common web security pitfalls such as persistent browser storage and unsafe string-based DOM manipulation.
Audit Metadata