frame-macos-notification
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the Tailwind CSS Play CDN (
cdn.tailwindcss.com) and Google Fonts (fonts.googleapis.com) to render the notification UI. These are well-known services used for front-end development and do not represent a security risk in this context. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data such as application names, notification titles, and message bodies to populate the HTML template.
- Ingestion points: Data enters the template via the
SKILL.mdinstructions which guide the agent on how to use user content. - Boundary markers: None explicitly defined in the template structure.
- Capability inventory: The skill generates HTML/CSS for rendering within a local preview environment. No file-write or network-write capabilities are requested.
- Sanitization: There are no specific sanitization instructions for the user input; however, the scope is limited to UI generation.
Audit Metadata