threejs-assets
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for processing user-supplied 3D files and uploads, creating an ingestion surface for untrusted data.
- Ingestion points:
SKILL.md(mentions "user-supplied 3D files" and "user uploads"). - Boundary markers: No specific delimiters are defined in the instructions to separate data from agent instructions.
- Capability inventory: Three.js asset management, loading, and metadata inventorying.
- Sanitization: The skill advises validating assets, limiting complexity, and handling malformed files.
- [EXTERNAL_DOWNLOADS]: The skill refers to official Three.js documentation and mentions resolving URLs for external decoder and transcoder binaries (Draco, KTX2), which are standard dependencies for 3D web applications.
Audit Metadata