jfb-action-messages
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is strictly instructional, offering PHP and JavaScript examples for developers extending JetFormBuilder. No executable code or malicious commands are present.
- [SAFE]: Documentation includes explicit security advice, reminding users that while the messaging system supports dynamic content (macros), output should remain HTML-escaped by the platform pipeline to prevent XSS.
- [SAFE]: External references are limited to official vendor documentation on GitHub (Crocoblock), which is consistent with the skill's stated purpose.
- [SAFE]: Variable placeholders such as
%email%and%form_id%are identified correctly as standard plugin macros rather than sensitive data exfiltration patterns.
Audit Metadata