masked-reveal

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a documentation-focused component for implementing a specific visual effect. It does not contain any malicious code, external exfiltration, or obfuscation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes text from the DOM to create a split-text effect. While this involves ingesting external data, the implementation is secure.
  • Ingestion points: Text is retrieved from DOM elements matching [data-masked-reveal] via element.textContent in SKILL.md.
  • Boundary markers: Not applicable to this UI utility.
  • Capability inventory: The skill modifies the DOM using element.innerHTML to wrap words in spans.
  • Sanitization: The code includes a robust escapeHTML function that sanitizes word content before it is inserted into the DOM, preventing Cross-Site Scripting (XSS) or injection attacks.
  • [COMMAND_EXECUTION]: No shell commands or system-level execution patterns were detected.
  • [EXTERNAL_DOWNLOADS]: The skill references GSAP and ScrollTrigger, which are well-known and trusted front-end animation libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:59 PM
Security Audit — agent-trust-hub — masked-reveal