build-threejs-scroll-worlds

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions in SKILL.md encourage the agent to ingest external user data, including "subject, audience, and ordered story beats" and "approved reference or working scene." There are no explicit instructions for the agent to use boundary markers or to sanitize this untrusted content before incorporating it into the generated Three.js application code.
  • Ingestion points: SKILL.md (e.g., "Start with the output, not the template" section).
  • Boundary markers: Absent.
  • Capability inventory: Generation of JavaScript (Three.js), HTML, and CSS for execution in a web browser.
  • Sanitization: Absent.
  • [EXTERNAL_DOWNLOADS]: SKILL.md references the public GitHub repository https://github.com/oso95/scroll-world as a technical reference. This is a well-known service and the reference is documented neutrally.
  • [OBFUSCATION]: demo/secret-pathways-assets/fonts.css contains large Base64-encoded strings. Analysis confirms these are legitimate WOFF2 font data URIs used for rendering text in the 3D world and do not contain hidden executable commands or malicious instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:34 AM
Security Audit — agent-trust-hub — build-threejs-scroll-worlds