image-first-grid-layout
Fail
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [OBFUSCATION]: The file demo/index.html contains a significant Base64-encoded string (encodedHtml) that obfuscates the full source code of the demonstration including its logic and structure.
- [DYNAMIC_EXECUTION]: The skill dynamically decodes the Base64-encoded implementation at runtime and injects it into a sandboxed iframe using the srcdoc attribute, which allows for the execution of hidden JavaScript.
- [EXTERNAL_DOWNLOADS]: The skill and its metadata reference external assets and scripts hosted on trusted services such as Google Fonts, Cloudflare CDN (for GSAP), and Supabase.
Recommendations
- AI detected serious security threats
Audit Metadata