h5p-player-setup

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs downloading the H5P player script and service worker from the jsDelivr CDN, and the @missing-elements/h5p-offline-player package from NPM. These are legitimate resources belonging to the official vendor.\n- [REMOTE_CODE_EXECUTION]: The component registers a browser Service Worker to handle local file serving from H5P archives. This utilizes code from the skill's author to enable intended offline playback functionality.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and render .h5p archives from external URLs, representing a surface for processing remote data.\n
  • Ingestion points: The 'src' parameter in the tag and the embed iframe URLs located in SKILL.md.\n
  • Boundary markers: None; the player is built to ingest the full contents of the target archive.\n
  • Capability inventory: Network request interception via Service Worker and DOM manipulation for content rendering.\n
  • Sanitization: Relies on the internal security and isolation mechanisms of the H5P core runtime library.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 01:28 PM
Security Audit — agent-trust-hub — h5p-player-setup