webgl-3d-object

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [OBFUSCATION]: The file demo/index.html contains a large Base64-encoded string (encodedHtml). This string decodes to the full HTML source for a design demo. While this technique hides the content from plain-text scanning, analysis shows it is a legitimate method for bundling a sandboxed preview within a single file.
  • [EXTERNAL_DOWNLOADS]: The skill references external assets and runtime scripts from well-known and trusted providers including Cloudflare (for GSAP and ScrollTrigger libraries), Supabase (for project assets), and Google Fonts. These dependencies are standard for the intended functionality.
  • [DYNAMIC_EXECUTION]: The demo implementation in demo/index.html dynamically decodes HTML content and injects it into a sandboxed iframe using srcdoc. It also uses URL.createObjectURL to manage assets. These mechanisms are standard for providing a restricted, self-contained preview environment for web components.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 05:24 PM
Security Audit — agent-trust-hub — webgl-3d-object