rendering-untrusted-content
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely instructional and promotes defensive programming. It provides technical guidance on identifying and fixing XSS sinks in both server-side templates and client-side JavaScript.- [EXTERNAL_DOWNLOADS]: The code snippets reference standard, well-known libraries like markdown, nh3 (a robust HTML sanitizer), and markupsafe. These are industry-standard tools for the tasks described and their usage is documented neutrally as a security best practice.- [COMMAND_EXECUTION]: The skill provides grep command examples intended for local code auditing. These are benign utility commands meant to be run by a developer to find patterns like innerHTML or |safe that require security review.
Audit Metadata