jfb-action-messages

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is strictly instructional, offering PHP and JavaScript examples for developers extending JetFormBuilder. No executable code or malicious commands are present.
  • [SAFE]: Documentation includes explicit security advice, reminding users that while the messaging system supports dynamic content (macros), output should remain HTML-escaped by the platform pipeline to prevent XSS.
  • [SAFE]: External references are limited to official vendor documentation on GitHub (Crocoblock), which is consistent with the skill's stated purpose.
  • [SAFE]: Variable placeholders such as %email% and %form_id% are identified correctly as standard plugin macros rather than sensitive data exfiltration patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:06 PM
Security Audit — agent-trust-hub — jfb-action-messages