frame-light-leak-cinema

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to generate static HTML and CSS for visual frames. No dangerous command execution or system access patterns were detected.- [EXTERNAL_DOWNLOADS]: The example HTML references resources from well-known services, including Tailwind CSS (cdn.tailwindcss.com) and Google Fonts (fonts.googleapis.com). These are standard industry tools for web design and do not pose a security risk in this context.- [DATA_EXPOSURE]: The skill identifies an indirect prompt injection surface as it accepts user-provided titles and metadata for interpolation into the generated HTML. While this creates a potential surface for instructions embedded in user data to be processed, the risk is localized to the presentation layer of the generated frame.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 12:15 PM
Security Audit — agent-trust-hub — frame-light-leak-cinema