skills/dzhng/skills/renderer/Gen Agent Trust Hub

renderer

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill recommends executing Blender in headless mode (blender -b --python script.py) to generate assets from scripts stored in the repository.
  • [DYNAMIC_EXECUTION]: The architecture involves running Python scripts via the Blender CLI, which constitutes dynamic execution of local scripts. If the agent generates these scripts based on untrusted user input, it could lead to arbitrary code execution within the Blender environment.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the math package from npm while providing a link to the pmndrs/math GitHub repository. The math package on npm is an unrelated, deprecated package; the correct package for the provided repository is @pmndrs/math. This naming discrepancy poses a dependency confusion risk.
  • [INDIRECT_PROMPT_INJECTION]: The renderer is designed to process external inputs such as "game observation, a query result, a document". This creates a surface where malicious instructions embedded in these external data sources could attempt to influence the agent's behavior during the rendering process or asset generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 02:25 PM
Security Audit — agent-trust-hub — renderer