globe-particles
Fail
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [OBFUSCATION]: The
demo/index.htmlfile contains a large Base64-encoded string (encodedHtml) that conceals the entire HTML document and associated script logic of the demo. This hides the interactive behavior and dependencies from standard static analysis tools. - [DYNAMIC_EXECUTION]: The skill uses dynamic execution in multiple forms:
- The
demo/index.htmlscript decodes theencodedHtmlpayload and injects it into an iframe via thesrcdocattribute, resulting in the runtime execution of hidden scripts. - The
SKILL.mdfile defines vertex and fragment shaders as template strings that are compiled by the Three.js library during runtime initialization. - [REMOTE_CODE_EXECUTION]: The decoded payload in the demo environment dynamically loads external JavaScript libraries (Three.js, GSAP, Iconify) from public CDNs. While these services are reputable, the automated execution triggered by the obfuscated payload bypasses visibility.
- [EXTERNAL_DOWNLOADS]: The skill and its demo reference and fetch resources from several external services:
- Libraries are retrieved from
cdnjs.cloudflare.comandcode.iconify.design. - Fonts and associated styling are fetched from
fonts.googleapis.com,fonts.gstatic.com, andapi.fontshare.com. - Demo image assets are hosted on Supabase storage (
hoirqrkdgbmvpwutwuwj.supabase.co). - Runtime CSS processing is referenced from
cdn.tailwindcss.com. - [INDIRECT_PROMPT_INJECTION]: The
initGlobeParticlesfunction ingests user-controlled options (e.g.,sphereCount,accentColor) that are directly interpolated into the Three.js scene setup and shaders. The absence of strict input validation or boundary markers creates an attack surface for indirect prompt injection if these inputs are sourced from untrusted data in an automated pipeline.
Recommendations
- AI detected serious security threats
Audit Metadata