3d-web-experience

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references standard development packages (e.g., @react-three/fiber, @gltf-transform/cli) and includes an example loading a 3D scene from Spline's official domain (https://prod.spline.design/xxx/scene.splinecode). These are routine resources for the stated purpose of 3D web development.
  • [COMMAND_EXECUTION]: The skill provides instructions for optimizing 3D models using the @gltf-transform/cli tool via the command line. These commands are standard utility operations for asset optimization.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a pipeline for ingesting and processing external 3D model files (GLB, GLTF, FBX).
  • Ingestion points: useGLTF('/model.glb') in SKILL.md and gltf-transform optimize commands.
  • Boundary markers: None explicitly defined for file processing.
  • Capability inventory: The skill uses standard Three.js loaders and a specific CLI tool for model optimization.
  • Sanitization: None detected; the skill relies on standard library implementations for parsing 3D file formats.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:18 AM
Security Audit — agent-trust-hub — 3d-web-experience