malloy-html-data-app-embedding

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as documentation for the Publisher.embed function and does not contain executable malicious code or instructions to bypass safety guidelines.
  • [DATA_EXFILTRATION]: The instructions include security best practices, warning users about the risks of authentication tokens leaking through URL headers and advising against moving query results to external hosts.
  • [REMOTE_CODE_EXECUTION]: While the skill mentions loading an external SDK script, it uses placeholder URLs and emphasizes treating embedded code as strictly first-party, warning against loading untrusted third-party scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:02 AM
Security Audit — agent-trust-hub — malloy-html-data-app-embedding