javascript-inline
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is based on community standards from frontendchecklist.io and provides best practices for improving application security via Content Security Policy (CSP) compliance.
- [PROMPT_INJECTION]: The skill performs code reviews on untrusted project data. Ingestion points: JavaScript scripts and HTML files processed during the 'Code Review' task in SKILL.md. Boundary markers: Absent; instructions do not specify delimiters for untrusted content. Capability inventory: Restricted to reporting and analysis in SKILL.md. Sanitization: No sanitization of user-provided code is performed before analysis.
- [COMMAND_EXECUTION]: A migration utility script using Node.js 'fs' and 'cheerio' is included in references/rule.md. This is a provided example for developers to automate code refactoring and is not designed for autonomous execution by the agent.
Audit Metadata