webgl
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill implements dynamic shader compilation using WebGL APIs (
gl.compileShader,gl.linkProgram) to convert string-based source code into GPU programs. To mitigate potential GPU hangs or resource exhaustion, the skill includes avalidateShaderSourcepattern that checks for infinite loops and suspicious keywords.- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of shader source code which may come from untrusted external sources, creating an indirect prompt injection surface. - Ingestion points: Shader source strings processed in
SKILL.mdandreferences/security-examples.md. - Boundary markers: None defined for the AI agent context.
- Capability inventory: Shader compilation and rendering commands (
gl.drawArrays,gl.drawElements) documented inSKILL.md. - Sanitization: The skill provides a
validateShaderSourceimplementation inreferences/security-examples.mdto detect and block malicious shader patterns.
Audit Metadata