html-coder
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references standard web development assets from established and well-known providers, including Google Fonts, jsDelivr, UNPKG, and Tailwind CSS. These resources are used to load common stylesheets and JavaScript libraries and do not involve suspicious or unknown sources.
- [SAFE]: The documentation actively promotes security best practices, including the implementation of Content Security Policy (CSP) and the use of Subresource Integrity (SRI) hashes for external script verification.
- [SAFE]: Deployment instructions for the
publish_artifacttool follow the principle of least privilege, requiring dedicated project subdirectories and explicitly warning against bundling the entire workspace root. - [SAFE]: The skill metadata includes a dedicated risk assessment section that correctly identifies common supply-chain risks in web development and provides appropriate mitigation strategies for developers.
Audit Metadata