masked-reveal
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a documentation-focused component for implementing a specific visual effect. It does not contain any malicious code, external exfiltration, or obfuscation.
- [INDIRECT_PROMPT_INJECTION]: The skill processes text from the DOM to create a split-text effect. While this involves ingesting external data, the implementation is secure.
- Ingestion points: Text is retrieved from DOM elements matching
[data-masked-reveal]viaelement.textContentinSKILL.md. - Boundary markers: Not applicable to this UI utility.
- Capability inventory: The skill modifies the DOM using
element.innerHTMLto wrap words in spans. - Sanitization: The code includes a robust
escapeHTMLfunction that sanitizes word content before it is inserted into the DOM, preventing Cross-Site Scripting (XSS) or injection attacks. - [COMMAND_EXECUTION]: No shell commands or system-level execution patterns were detected.
- [EXTERNAL_DOWNLOADS]: The skill references GSAP and ScrollTrigger, which are well-known and trusted front-end animation libraries.
Audit Metadata