website-building

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references numerous external assets such as fonts (Google Fonts, Fontshare), icons (Lucide, Phosphor), and utility libraries (GSAP, Chart.js, Three.js) via well-known CDNs like JSDelivr, Unpkg, and ESM.sh. These are standard industry practices for web development.
  • [COMMAND_EXECUTION]: Provides standard development and build commands using Bun, NPM, Esbuild, and Vite. It also includes a custom Playwright-based testing script (game/scripts/web_game_playwright_client.js) for automated browser QA and state verification, which is appropriate for the domain.
  • [SAFE]: No malicious instructions, prompt injections, data exfiltration patterns, or obfuscated payloads were found. The skill emphasizes security best practices, such as proper environment variable management for API keys and avoiding insecure browser storage in restricted environments.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 03:02 PM
Security Audit — agent-trust-hub — website-building