html-artifact

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides explicit instructions to prevent security vulnerabilities. For example, SKILL.md mandates that supplied content be treated as data rather than executable markup and forbids the inclusion of credentials or telemetry in the generated artifacts.
  • [SAFE]: Data handling practices are prioritized, with guidelines in references/code-change-review.md and references/interactive-projections.md requiring that untrusted data like code diffs and repository files be rendered as escaped text.
  • [SAFE]: Dependency management is addressed through a dedicated references/dependency-policy.md, which emphasizes staticization, bundling, and avoiding remote code execution from CDNs unless specifically justified and secured.
  • [SAFE]: The provided assets (assets/base.html, assets/carousel-control.html, etc.) contain benign JavaScript and CSS used for standard UI interactions like theme switching and content navigation.
  • [SAFE]: No evidence of prompt injection, data exfiltration, or persistence mechanisms was found. The skill appears to follow security best practices for agent-generated web content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:42 AM
Security Audit — agent-trust-hub — html-artifact