image-first-grid-layout

Fail

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [OBFUSCATION]: The file demo/index.html contains a significant Base64-encoded string (encodedHtml) that obfuscates the full source code of the demonstration including its logic and structure.
  • [DYNAMIC_EXECUTION]: The skill dynamically decodes the Base64-encoded implementation at runtime and injects it into a sandboxed iframe using the srcdoc attribute, which allows for the execution of hidden JavaScript.
  • [EXTERNAL_DOWNLOADS]: The skill and its metadata reference external assets and scripts hosted on trusted services such as Google Fonts, Cloudflare CDN (for GSAP), and Supabase.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 25, 2026, 03:09 AM
Security Audit — agent-trust-hub — image-first-grid-layout