present
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill includes explicit security constraints for the generated HTML content, requiring it to be self-contained with no CDN links, external fonts, or network requests. This prevents potential data exfiltration via the user's browser.
- [COMMAND_EXECUTION]: The skill instructs the agent to use the
opencommand to display a file from the system temporary directory ($TMPDIR). This usage is consistent with the skill's primary purpose of visualizing data and does not represent an unauthorized command execution risk. - [SAFE]: While the skill processes external data (results of analysis or research), it instructs the creation of a 'throwaway artifact' for local viewing only. The instruction to keep the file in the temp directory and offline reduces the risk of malicious payload persistence or external communication.
Audit Metadata