malloy-html-data-app-embedding
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as documentation for the
Publisher.embedfunction and does not contain executable malicious code or instructions to bypass safety guidelines. - [DATA_EXFILTRATION]: The instructions include security best practices, warning users about the risks of authentication tokens leaking through URL headers and advising against moving query results to external hosts.
- [REMOTE_CODE_EXECUTION]: While the skill mentions loading an external SDK script, it uses placeholder URLs and emphasizes treating embedded code as strictly first-party, warning against loading untrusted third-party scripts.
Audit Metadata