create-scene

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Uses the official @dcl/sdk-commands via npx for project initialization and local previewing, which is the standard developer workflow for the platform.
  • [EXTERNAL_DOWNLOADS]: Fetches 3D model assets (GLB files) from models.dclregenesislabs.xyz using curl. These are static assets (non-executable) and the domain is associated with the Decentraland developer community.
  • [DATA_EXFILTRATION]: Documents the use of platform-specific permissions such as USE_FETCH and ALLOW_MEDIA_HOSTNAMES. These are standard requirements for scene functionality within the Decentraland runtime and are not used here for malicious data extraction.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 11:58 AM
Security Audit — agent-trust-hub — create-scene