webgl

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill implements dynamic shader compilation using WebGL APIs (gl.compileShader, gl.linkProgram) to convert string-based source code into GPU programs. To mitigate potential GPU hangs or resource exhaustion, the skill includes a validateShaderSource pattern that checks for infinite loops and suspicious keywords.- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of shader source code which may come from untrusted external sources, creating an indirect prompt injection surface.
  • Ingestion points: Shader source strings processed in SKILL.md and references/security-examples.md.
  • Boundary markers: None defined for the AI agent context.
  • Capability inventory: Shader compilation and rendering commands (gl.drawArrays, gl.drawElements) documented in SKILL.md.
  • Sanitization: The skill provides a validateShaderSource implementation in references/security-examples.md to detect and block malicious shader patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:54 PM
Security Audit — agent-trust-hub — webgl