AgentPod is building a private, secure device for your AI agent.The AgentPod device is coming.Coming soonBe first
We checked this and rejected itsecurity

html-artifacts: why it is not safe to use

Our review found no material security or privacy issues in html-artifacts based on the inspected repository files.

What we found

Our review of `dogum/html-artifacts` did not identify a security or privacy issue that would block use. In the inspected repository files, the skill is instruction-only and clearly states when it should trigger and what output format it uses. We did not find hidden or disguised instructions, hardcoded credentials, dangerous commands, obfuscated payloads, or attempts to bypass confirmation.

We also did not find instructions to access environment variables, keychains, browser data, SSH keys, or other sensitive credentials. The skill prefers single-file offline HTML and does not require network calls at view time or fetch remote code from undisclosed sources. The README mentions optional user-chosen destinations such as S3 or Notion, but leaves that decision to the user rather than sending data automatically.

What to do instead

If you plan to use this skill, apply normal operational review rather than remediation for a specific security finding. Confirm any sharing destination you choose, verify what content is included in exported HTML artifacts, and keep storage targets aligned with your own data handling rules. If your environment has stricter controls, review future updates to ensure these properties remain unchanged.

Want the same outcome, safely? Use our checked skill instead.

Source: https://github.com/dogum/html-artifacts

We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.

Copied to clipboard. Paste it into your AI (ChatGPT, Claude, or your agent) to add the skill.