threejs-postprocessing

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No attempts to override agent behavior or bypass safety constraints were found. The instructions are focused entirely on technical guidance for three.js.
  • [DATA_EXFILTRATION]: No sensitive file paths or unauthorized network operations were detected. All external links point to the official threejs.org documentation.
  • [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or secrets are present. The skill explicitly advises against hardcoding sensitive information in its 'Gotchas' section.
  • [REMOTE_CODE_EXECUTION]: The skill does not contain commands to download or execute remote scripts. It provides high-level workflow steps rather than executable code blocks.
  • [OBFUSCATION]: No encoded content, zero-width characters, or hidden text patterns were identified in the files.
  • [DYNAMIC_EXECUTION]: There are no uses of eval(), exec(), or other dynamic code generation techniques.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — threejs-postprocessing