masked-reveal
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides legitimate instructions for UI development and does not contain any malicious patterns or hidden instructions.\n- [INDIRECT_PROMPT_INJECTION]: While the skill processes dynamic text content, it includes a robust
escapeHTMLfunction to sanitize input before re-rendering, which effectively mitigates cross-site scripting (XSS) and injection risks in the rendered output.\n- [DATA_EXPOSURE]: No hardcoded credentials, sensitive system paths, or unauthorized network communication patterns were identified.\n- [REMOTE_CODE_EXECUTION]: The skill does not perform any external package installations or execute remote scripts; it relies on the pre-existence of the GSAP library in the developer's environment.
Audit Metadata