gleam-web-development
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a comprehensive developer guide for the Gleam Wisp and Mist frameworks without including malicious code or hidden instructions.
- [EXTERNAL_DOWNLOADS]: The skill references official documentation and repositories from hexdocs.pm and GitHub (lpil/wisp). These are well-known, trusted sources for the Gleam ecosystem and are documented neutrally.
- [SAFE]: The code examples demonstrate strong security hygiene, specifically recommending
wisp.csrf_known_header_protectionfor all state-changing requests and explicitly instructing the user toALWAYS escape user inputusingwisp.escape_htmlto prevent XSS. - [SAFE]: The skill provides explicit warnings regarding untrusted input, such as the
file_namemetadata in file uploads, and demonstrates safe cookie handling using signed cookies to prevent tampering.
Audit Metadata