threejs-postprocessing
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No attempts to override agent behavior or bypass safety constraints were found. The instructions are focused entirely on technical guidance for three.js.
- [DATA_EXFILTRATION]: No sensitive file paths or unauthorized network operations were detected. All external links point to the official threejs.org documentation.
- [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or secrets are present. The skill explicitly advises against hardcoding sensitive information in its 'Gotchas' section.
- [REMOTE_CODE_EXECUTION]: The skill does not contain commands to download or execute remote scripts. It provides high-level workflow steps rather than executable code blocks.
- [OBFUSCATION]: No encoded content, zero-width characters, or hidden text patterns were identified in the files.
- [DYNAMIC_EXECUTION]: There are no uses of eval(), exec(), or other dynamic code generation techniques.
Audit Metadata