malloy-html-data-app-runtime
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and code patterns for building web applications using a specific data runtime. It includes explicit security guidance, advising against direct string interpolation of untrusted data and recommending the use of parameterized queries (
opts.givens) to prevent injection vulnerabilities. - [SAFE]: All network interactions and script loading patterns are standard for web development within the specified environment, such as using root-relative paths for SDK components and relative paths for application resources.
- [SAFE]: No malicious patterns such as prompt injection, data exfiltration to unauthorized external domains, or persistence mechanisms were identified in the provided documentation or code examples.
Audit Metadata