htmx-security
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill package contains only documentation and metadata. There is no executable code or automation that could perform unauthorized actions.
- [NO_CODE]: No scripts (Python, JavaScript, shell) or binaries are included. The functionality is purely instructional.
- [INDIRECT_PROMPT_INJECTION]: Although the skill is intended to process and review potentially untrusted user content (HTML fragments), it lacks the capabilities (such as file writing, shell execution, or network requests) required to turn an injection into a functional exploit.
- [DATA_EXPOSURE]: No hardcoded credentials, sensitive file paths, or data exfiltration patterns were detected.
Audit Metadata