qa-review

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were identified during the analysis of the instructions and reference templates.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No hardcoded credentials, sensitive file path access, or unauthorized network operations were detected. The external URL in the metadata points to the author's official GitHub profile, which is consistent with the provided vendor context.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform any remote code execution, package installation, or dynamic script generation. It relies on standard internal MCP tools for asset inspection.
  • [INDIRECT_PROMPT_INJECTION]: While the skill involves processing external data (Blender assets and metadata), the ingestion points are limited to visual and technical data (screenshots, polycounts). No high-risk processing of untrusted text that could lead to indirect prompt injection was identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 04:42 AM
Security Audit — agent-trust-hub — qa-review