cli-anything-threemf
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
cli-anything-3mftool directly from the HKUDS GitHub repository. This is a legitimate vendor resource used for its intended purpose and does not trigger a high-severity warning per trust scope guidelines. - [COMMAND_EXECUTION]: Utilizes system-level commands to install dependencies via pip and to execute mesh manipulation routines such as
info,inspect, andrepairon user-provided files. - [INDIRECT_PROMPT_INJECTION]: As the skill processes external 3D model files (3MF) using automated tools, it possesses an attack surface for indirect injection. Maliciously crafted mesh metadata or geometry could theoretically target vulnerabilities in the underlying mesh processing library, although the impact is contained within the model manipulation context.
Audit Metadata