cgv-script

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns such as credential theft, data exfiltration to external domains, or unauthorized system access were detected.
  • [COMMAND_EXECUTION]: The skill generates client-side JavaScript code to be manually pasted into a specific form builder platform. The execution context is limited to the platform's own runtime environment and provided APIs.
  • [SAFE]: The skill implements strict stability guidelines (Rule §0 and Rule §1) that mandate the use of idempotency guards and forbid blocking operations, which protects the host application from performance degradation and crashes.
  • [PROMPT_INJECTION]: While the skill processes user-provided business descriptions into executable code (representing an indirect injection surface), it utilizes a structured decision tree and predefined templates to validate and constrain the output generation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 03:35 AM
Security Audit — agent-trust-hub — cgv-script