threejs-dynamic-surface-effects
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a technical implementation guide for Three.js developers. No malicious patterns, obfuscation, or security vulnerabilities were identified.
- [PROMPT_INJECTION]: No instructions attempting to override agent behavior, bypass safety filters, or extract system prompts were found.
- [DATA_EXFILTRATION]: The skill does not access sensitive files (such as .ssh, .aws, or .env) or perform network operations to non-whitelisted domains. There are no hardcoded credentials.
- [REMOTE_CODE_EXECUTION]: No remote script downloads (e.g., curl|bash) or execution of untrusted external code were detected. The skill references standard Three.js imports.
- [COMMAND_EXECUTION]: No suspicious shell commands, privilege escalation attempts (sudo), or persistence mechanisms were found.
- [DYNAMIC_EXECUTION]: While the skill discusses runtime shader generation (TSL), this is a standard and safe practice within the context of WebGPU rendering and does not involve executing untrusted input on the host system.
Audit Metadata