three-raycast-interaction

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to provide instructional code for 3D interactions. The logic is self-contained and operates within standard browser and WebGL boundaries.
  • [COMMAND_EXECUTION]: There are no attempts to execute shell commands, perform privilege escalation, or access system-level resources.
  • [DATA_EXFILTRATION]: No network operations, credential harvesting, or access to sensitive environment variables or local files (such as .ssh or .aws) were found.
  • [EXTERNAL_DOWNLOADS]: The skill references the three library (version 0.169.0), which is a well-known and trusted package. No unverifiable or remote script executions are present.
  • [INDIRECT_PROMPT_INJECTION]: While the skill handles user pointer input, it does not process natural language instructions or interpolate untrusted data into agent prompts, presenting no injection risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 05:49 PM
Security Audit — agent-trust-hub — three-raycast-interaction