threejs-tresjs
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill primarily consists of architectural patterns and code snippets for 3D interface development.
- [INDIRECT_PROMPT_INJECTION]: The implementation patterns include surfaces for untrusted data such as HUD text and color properties. Ingestion points: 'props.title' and 'userInput' strings used in 3D rendering components. Boundary markers: Absent from snippets. Capability inventory: WebGL rendering, Three.js scene management, and GPU resource allocation. Sanitization: Present; the skill demonstrates regex-based filtering for XSS and strict pattern validation for color strings to mitigate ReDoS vulnerabilities.
- [REMOTE_CODE_EXECUTION]: The skill references standard development tools and well-known libraries, with no evidence of remote script execution or untrusted downloads.
Audit Metadata