nested-container-clean-agency

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The demo/index.html file stores the demo template as a Base64-encoded string (encodedHtml) to package the design within the sandboxed environment.\n- [DYNAMIC_EXECUTION]: The demo logic dynamically decodes asset data using atob() and generates object URLs for rendering media, restricted to a sandboxed iframe context.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted product briefs and design references from external sites, creating a surface for potential injection.\n
  • Ingestion points: Design brief inputs in demo/PROMPT.md and reference URLs.\n
  • Boundary markers: None.\n
  • Capability inventory: Generates HTML output and renders design components.\n
  • Sanitization: Not explicitly implemented.\n- [EXTERNAL_DOWNLOADS]: The skill references and fetches assets from Supabase storage and well-known services including Google Fonts, Fontshare, Tailwind CSS, and Iconify.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 03:10 AM
Security Audit — agent-trust-hub — nested-container-clean-agency