anywidget-generator
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard implementation guidelines for UI components within the marimo ecosystem. No malicious patterns, such as command injection, obfuscation, or data exfiltration, were detected.
- [INDIRECT_PROMPT_INJECTION]: While the skill involves generating code based on user requests, it proactively addresses potential security risks by instructing the agent to never read files outside the project scope and explicitly listing sensitive paths (e.g., ~/.ssh, ~/.env, /etc/) that must be avoided. It also requires the use of relative paths for local file access, minimizing the risk of directory traversal attacks.
Audit Metadata