implicit-cad
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Spawns local Node.js and Python processes using
subprocess.run,subprocess.Popen, andspawnSyncto coordinate build, export, and generation tasks. Evidence found inscripts/packages/cadgen/src/cadgen/_internal/node_runtime.py,scripts/packages/cadgen/src/cadgen/implicit_export.py, andscripts/export.mjs. - [REMOTE_CODE_EXECUTION]: Utilizes dynamic JavaScript code evaluation and module loading via
new Functionandimport()on data URLs to implement a GLSL-to-JS compiler and load user-defined CAD models. Relevant files includescripts/packages/implicitjs/src/lib/implicitCad/loader.jsandscripts/packages/implicitjs/src/lib/implicitCad/sdfCompiler.js. - [EXTERNAL_DOWNLOADS]: Fetches rendering environment maps and textures from
https://static.morflax.cominscripts/packages/implicitjs/src/common/themeSettings.js. This is used for standard rendering functionality. - [PROMPT_INJECTION]: The skill processes user-authored JavaScript files as executable modules, which introduces a potential surface for indirect injection if an agent is tricked into processing a malicious model definition.
- Ingestion points:
scripts/packages/implicitjs/src/lib/implicitCad/loader.js(dynamic module import). - Boundary markers: Absent. The skill does not use delimiters or ignore instructions when importing user-defined modules.
- Capability inventory: Subprocess process spawning, file system writing, and dynamic code compilation across various scripts.
- Sanitization: Absent. JavaScript module contents are not sanitized before execution.
Audit Metadata