skills/sfrmrc/skills/corner-diagonals/Gen Agent Trust Hub

corner-diagonals

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [OBFUSCATION]: The file demo/index.html contains a large Base64-encoded payload assigned to the encodedHtml variable. This payload decodes to a full HTML document including inline scripts, styles, and WebGL shader code.- [DYNAMIC_EXECUTION]: The demo/index.html script uses a custom decoder to transform the encodedHtml string into a document that is then executed within an iframe via the srcdoc property. This involves runtime string manipulation to inject script paths into the resulting document.- [EXTERNAL_DOWNLOADS]: The skill downloads necessary UI runtime libraries such as GSAP, Three.js, and Iconify, along with fonts, from well-known content delivery networks including Cloudflare, Google, and Tailwind.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 01:38 PM
Security Audit — agent-trust-hub — corner-diagonals