threejs-materials-v2

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No security issues detected. The skill is composed of markdown instructions and JavaScript code examples for Three.js development. It contains no executable binaries, shell scripts, or unauthorized network operations.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to process user-supplied task descriptions. The risk is negligible as the skill lacks any autonomous execution capabilities or system tools that could be abused.
  • Ingestion points: User-provided task descriptions interpolated into the <task> placeholder within the examples in SKILL.md.
  • Boundary markers: None identified for user input.
  • Capability inventory: None. The skill contains no scripts, subprocess calls, or file system write operations.
  • Sanitization: None performed on the user-provided input strings.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 04:23 AM
Security Audit — agent-trust-hub — threejs-materials-v2