build-threejs-scroll-worlds
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions in
SKILL.mdencourage the agent to ingest external user data, including "subject, audience, and ordered story beats" and "approved reference or working scene." There are no explicit instructions for the agent to use boundary markers or to sanitize this untrusted content before incorporating it into the generated Three.js application code. - Ingestion points:
SKILL.md(e.g., "Start with the output, not the template" section). - Boundary markers: Absent.
- Capability inventory: Generation of JavaScript (Three.js), HTML, and CSS for execution in a web browser.
- Sanitization: Absent.
- [EXTERNAL_DOWNLOADS]:
SKILL.mdreferences the public GitHub repositoryhttps://github.com/oso95/scroll-worldas a technical reference. This is a well-known service and the reference is documented neutrally. - [OBFUSCATION]:
demo/secret-pathways-assets/fonts.csscontains large Base64-encoded strings. Analysis confirms these are legitimate WOFF2 font data URIs used for rendering text in the 3D world and do not contain hidden executable commands or malicious instructions.
Audit Metadata