3d-model-generation

Warn

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: Deceptive metadata identified. The skill's internal metadata claims authorship by 'eachlabs', which conflicts with the verified author identity 'marcoamu' provided in the context.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it is designed to ingest and process real-time data from an external API (eachlabs.run) via Server-Sent Events. Ingestion points: SSE events from the each::sense chat endpoint. Boundary markers: Absent. Capability inventory: Documentation encourages the agent to perform network requests and process external media. Sanitization: Absent.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to interact with external domains (sense.eachlabs.run and storage.eachlabs.ai) for asset generation and retrieval.
  • [NO_CODE]: No executable scripts or binary files were found within the skill package; the skill consists entirely of documentation and examples.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 11, 2026, 10:49 AM
Security Audit — agent-trust-hub — 3d-model-generation