skills/stylusnexus/agent-plugins/html/Gen Agent Trust Hub

html

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a secure workflow for generating static HTML artifacts. It explicitly mandates that all files must be self-contained, using only inline CSS and local-only JavaScript. It contains a comprehensive 'Safety checklist' that strictly forbids external scripts, remote fonts, network requests, analytics, and the inclusion of credentials or secrets.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data (such as code diffs and research reports) to generate its artifacts. While this creates a potential injection surface, the skill implements strong procedural guardrails.
  • Ingestion points: Workflow Step 2 in SKILL.md requires reading project files, diffs, and research.
  • Boundary markers: The skill relies on structured templates (template.html) rather than raw interpolation, reducing the risk of accidental execution.
  • Capability inventory: The skill leverages the agent's ability to write files to the artifacts/html/ directory.
  • Sanitization: The 'Safety checklist' explicitly directs the agent to scan the final output for <script src> tags, tracking pixels, and fetch calls, providing a critical verification step before the artifact is provided to the user.
  • [DYNAMIC_EXECUTION]: The template.html file includes a minimal, inline JavaScript function for local clipboard interaction. This script is strictly scoped to local functionality and does not facilitate remote code execution or network communication.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:18 PM
Security Audit — agent-trust-hub — html