webgl-3d-object
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [OBFUSCATION]: The file
demo/index.htmlcontains a large Base64-encoded string (encodedHtml). This string decodes to the full HTML source for a design demo. While this technique hides the content from plain-text scanning, analysis shows it is a legitimate method for bundling a sandboxed preview within a single file. - [EXTERNAL_DOWNLOADS]: The skill references external assets and runtime scripts from well-known and trusted providers including Cloudflare (for GSAP and ScrollTrigger libraries), Supabase (for project assets), and Google Fonts. These dependencies are standard for the intended functionality.
- [DYNAMIC_EXECUTION]: The demo implementation in
demo/index.htmldynamically decodes HTML content and injects it into a sandboxed iframe usingsrcdoc. It also usesURL.createObjectURLto manage assets. These mechanisms are standard for providing a restricted, self-contained preview environment for web components.
Audit Metadata