skills/sfrmrc/skills/masked-reveal/Gen Agent Trust Hub

masked-reveal

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The core animation logic in SKILL.md includes a helper function escapeHTML to sanitize text content before it is processed and re-inserted into the DOM, mitigating risks associated with untrusted data ingestion.
  • [EXTERNAL_DOWNLOADS]: The demo environment references external runtime dependencies, including GSAP and ScrollTrigger libraries from Cloudflare's CDN and icon resources from Iconify. These are well-known technology services and are used appropriately for the skill's functionality.
  • [SAFE]: The demo/index.html file bundles its demo content using a Base64 encoded string. Analysis of the decoded content reveals a standard HTML structure for a design preview with restrictive Content Security Policies, demonstrating a commitment to secure sandboxing rather than malicious obfuscation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 01:37 PM
Security Audit — agent-trust-hub — masked-reveal