nested-container-clean-agency
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The
demo/index.htmlfile stores the demo template as a Base64-encoded string (encodedHtml) to package the design within the sandboxed environment.\n- [DYNAMIC_EXECUTION]: The demo logic dynamically decodes asset data usingatob()and generates object URLs for rendering media, restricted to a sandboxed iframe context.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted product briefs and design references from external sites, creating a surface for potential injection.\n - Ingestion points: Design brief inputs in
demo/PROMPT.mdand reference URLs.\n - Boundary markers: None.\n
- Capability inventory: Generates HTML output and renders design components.\n
- Sanitization: Not explicitly implemented.\n- [EXTERNAL_DOWNLOADS]: The skill references and fetches assets from Supabase storage and well-known services including Google Fonts, Fontshare, Tailwind CSS, and Iconify.
Audit Metadata