nested-container-clean-agency

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEOBFUSCATIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The demo implementation in 'demo/index.html' uses a Base64-encoded string for the primary HTML payload of its sandboxed iframe. Decryption reveals standard HTML, CSS, and WebGL code for design visualization.
  • [EXTERNAL_DOWNLOADS]: The skill integrates resources from well-known services including Google Fonts, Tailwind CSS, Iconify, and Supabase. These are used for typography, styling, and asset hosting.
  • [DYNAMIC_EXECUTION]: The demo utilizes the 'srcdoc' attribute to dynamically load and execute the encoded HTML within a sandboxed 'iframe' element, which is a common pattern for design previews.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided text and references to generate layouts. While this creates a data ingestion surface, the output is restricted to design generation and the included demo is sandboxed.
  • [INDIRECT_PROMPT_INJECTION]: Ingestion points: 'demo/PROMPT.md' (product brief, content anchors). Boundary markers: Absent. Capability inventory: HTML/JS generation in 'demo/index.html'. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:31 AM
Security Audit — agent-trust-hub — nested-container-clean-agency