threejs-dynamic-surface-effects

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a technical implementation guide for Three.js developers. No malicious patterns, obfuscation, or security vulnerabilities were identified.
  • [PROMPT_INJECTION]: No instructions attempting to override agent behavior, bypass safety filters, or extract system prompts were found.
  • [DATA_EXFILTRATION]: The skill does not access sensitive files (such as .ssh, .aws, or .env) or perform network operations to non-whitelisted domains. There are no hardcoded credentials.
  • [REMOTE_CODE_EXECUTION]: No remote script downloads (e.g., curl|bash) or execution of untrusted external code were detected. The skill references standard Three.js imports.
  • [COMMAND_EXECUTION]: No suspicious shell commands, privilege escalation attempts (sudo), or persistence mechanisms were found.
  • [DYNAMIC_EXECUTION]: While the skill discusses runtime shader generation (TSL), this is a standard and safe practice within the context of WebGPU rendering and does not involve executing untrusted input on the host system.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 07:20 PM
Security Audit — agent-trust-hub — threejs-dynamic-surface-effects