background-grid-webgl
Pass
Audited by Gen Agent Trust Hub on Jul 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The reference implementation fetches runtime libraries from well-known services including Tailwind CSS, Iconify, and Google Fonts.
- [EXTERNAL_DOWNLOADS]: Design assets are referenced from Supabase, a well-known infrastructure provider.
- [PROMPT_INJECTION]: The skill demonstrates an indirect prompt injection surface by ingesting external product briefs. Evidence Chain: (1) Ingestion points: Product brief and content anchors in demo/PROMPT.md; (2) Boundary markers: Absent; (3) Capability inventory: Client-side WebGL shader execution and HTML/JS rendering; (4) Sanitization: Absent.
- [SAFE]: No malicious obfuscation, credential theft, or persistence mechanisms were found within the skill instructions or scripts.
Audit Metadata