implicit-cad

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Spawns local Node.js and Python processes using subprocess.run, subprocess.Popen, and spawnSync to coordinate build, export, and generation tasks. Evidence found in scripts/packages/cadgen/src/cadgen/_internal/node_runtime.py, scripts/packages/cadgen/src/cadgen/implicit_export.py, and scripts/export.mjs.
  • [REMOTE_CODE_EXECUTION]: Utilizes dynamic JavaScript code evaluation and module loading via new Function and import() on data URLs to implement a GLSL-to-JS compiler and load user-defined CAD models. Relevant files include scripts/packages/implicitjs/src/lib/implicitCad/loader.js and scripts/packages/implicitjs/src/lib/implicitCad/sdfCompiler.js.
  • [EXTERNAL_DOWNLOADS]: Fetches rendering environment maps and textures from https://static.morflax.com in scripts/packages/implicitjs/src/common/themeSettings.js. This is used for standard rendering functionality.
  • [PROMPT_INJECTION]: The skill processes user-authored JavaScript files as executable modules, which introduces a potential surface for indirect injection if an agent is tricked into processing a malicious model definition.
  • Ingestion points: scripts/packages/implicitjs/src/lib/implicitCad/loader.js (dynamic module import).
  • Boundary markers: Absent. The skill does not use delimiters or ignore instructions when importing user-defined modules.
  • Capability inventory: Subprocess process spawning, file system writing, and dynamic code compilation across various scripts.
  • Sanitization: Absent. JavaScript module contents are not sanitized before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 02:30 PM