html-anythingCAUTION
✨ The agentic HTML editor — your local AI agent writes the HTML, you ship it. 🚀 75 Skills × 9 Surfaces (magazine · deck · poster · XHS / tweet · prototype · data report · Hyperframes) 🛡️ Sandboxed preview · 📤 1-click to WeChat / X / Zhihu / HTML / PNG 🔑 Zero API key — Claude Code / Cursor / Codex /
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
From the team behind Open Design — 40k★ · 200+ contributors, production-grade and iterating faster. html-anything is the focused agent-era HTML editor; if it clicks for you, Open Design is where the same team ships at scale.
Live page: open-design.ai/html-anything/ — overview, surface modes, and showcase before you clone.
Markdown is the draft. HTML is what humans read. Your local agent writes it. The agentic HTML editor — in the agentic era, you don't hand-edit docs anymore, so the output format should be what the reader actually wants: HTML. Local-first, zero API key, reuses the CLI session you already have logged in — 9 coding-agent CLIs auto-detected on yourPATH(Claude Code · Cursor Agent · Codex · Gemini CLI · GitHub Copilot CLI · OpenCode · Qwen Coder · Aider · IBM Bob), driven by 75 composable skill templates across 9 deliverable surfaces (magazine articles · keynote decks · résumés · posters · Xiaohongshu cards · tweet cards · web prototypes · data reports · Hyperframes videos). One-click export to WeChat / X / Zhihu, or download.html/.png.
3bfcf171063fOBSERVED · 2026-10-07Install
Commands as the repository documents them. They are shown, not run.
git clone https://github.com/nexu-io/html-anything.git
git clone https://github.com/nexu-io/html-anything.git
git clone https://github.com/nexu-io/html-anything
git clone https://github.com/nexu-io/html-anything
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| claude-desktop | mentioned | |
| codex | mentioned | |
| copilot | mentioned | |
| cursor | mentioned | |
| gemini-cli | mentioned | |
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: article-magazine zh_name: "杂志文章" en_name: "Magazine Article" emoji: "📖" description: "Substack / Medium 高级感长文排版, 适合公众号、博客发布" category: article scenario: marketing aspect_hint: "A4 / 长页面" featured: 11 tags: ["blog", "essay", "newsletter", "公众号", "博客", "文章"] example_id: sample-article-trq212-html example_name: "杂志文章 · HTML 取代 Markdown" example_format: markdown example_tagline: "灵感来自 @trq212 的推文" example_desc: "围绕「AI 时代 HTML > Markdown」的延伸评论, 含原推附注与可点击链接" example_source_url: "https://x.com/trq212/status/2052809885763747935" example_source_label: "@trq212 / x.com" --- 【模板: 杂志文章】 - 顶部 hero: 大标题 (text-5xl/6xl) + 可选副标题 + 作者 / 阅读时间 / 日期元数据。 - 正文: 单栏, 最大宽度约 700px, 居中。段落 `text-lg leading-relaxed text-neutral-700 dark:text-neutral-300`。 - H2 / H3 标题用 serif 字体, 让正文与标题有视觉对比。 - 引用块使用左侧粗 accent 色边线 + 斜体。 - 代码块: 圆角 + 深色背景 + 浅色文字, 显示语言标签。 - 列表项使用自定义 bullet(小方块 / accent 圆点)。 - 章节之间用 `<hr>` 分隔, 但样式做成中央居中的小 ornament。 - 文末加一个简单的 "如果觉得有用,欢迎转发" 行动卡片。
Trust audit
CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (24)
const MARK = "";
const intro = t("tasks.empty.intro", { query: "" }).split("");const MARK = "";
import { hostRejectedResponse, isHostAllowed } from "../../_lib/host-guard";const { GET } = await import("../../../app/api/marketplace/route");const { GET } = await import("../../../app/api/marketplace/route");const { POST } = await import("../../../app/api/marketplace/install/route");const { POST } = await import("../../../app/api/marketplace/install/route");const baseURL = `http://127.0.0.1:${webPort}`;const DEFAULT_BASE_URL = "http://127.0.0.1:3317";
const res = await GET(new Request("http://127.0.0.1/api/marketplace"));const req = new Request("http://127.0.0.1/api/marketplace/install", {const req = new Request("http://127.0.0.1/api/marketplace/install", {const family = "👨👩👧";
@types/node, tsx, typescript, vitest
@playwright/test, @types/node, jszip, tsx, typescript
clsx, diff, dompurify, highlight.js, idb, jszip, juice, lucide-react
tsx
`POST /api/convert` 走 SSE。Agent 的 stdout 是一行行 JSON-line,server 抽出其中的 `text` 字段,作为 SSE event 推下去,客户端 append 进 `iframe[srcdoc]`。整个过程跟在终端里看 AI 写代码一模一样,只不过最终产物是好看的 HTML 而不是 markdown。**不满意可以打断**,不浪费一整次 tok
docs/assets/banner.png
docs/screenshots/skills/frame-glitch-title.png
docs/screenshots/skills/frame-logo-outro.png
docs/screenshots/skills/vfx-text-cursor.png
curl -fsSL https://get.filebase.dev | sh</code></pre>
Gates applied: no_behavioural_pass.
3bfcf171063ffull audit observations/trust-audit/skill/nexu-io__html-anything.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 3bfcf171063f | CAUTION | B | 87 | first audit |
Questions
What does the html-anything skill do?
✨ The agentic HTML editor — your local AI agent writes the HTML, you ship it. 🚀 75 Skills × 9 Surfaces (magazine · deck · poster · XHS / tweet · prototype · data report · Hyperframes) 🛡️ Sandboxed preview · 📤 1-click to WeChat / X / Zhihu / HTML / PNG 🔑 Zero API key — Claude Code / Cursor / Codex /
Is html-anything safe to install?
With care. The audit graded it B (87/100) and found 24 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can html-anything access on my machine?
The audit observed that it reaches the network and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: none found.
Which assistants does html-anything work with?
Its documentation mentions claude-code, claude-desktop, codex, copilot, cursor, gemini-cli and openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (3bfcf171063f), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.