background-grid-webgl

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The reference implementation fetches runtime libraries from well-known services including Tailwind CSS, Iconify, and Google Fonts.
  • [EXTERNAL_DOWNLOADS]: Design assets are referenced from Supabase, a well-known infrastructure provider.
  • [PROMPT_INJECTION]: The skill demonstrates an indirect prompt injection surface by ingesting external product briefs. Evidence Chain: (1) Ingestion points: Product brief and content anchors in demo/PROMPT.md; (2) Boundary markers: Absent; (3) Capability inventory: Client-side WebGL shader execution and HTML/JS rendering; (4) Sanitization: Absent.
  • [SAFE]: No malicious obfuscation, credential theft, or persistence mechanisms were found within the skill instructions or scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 12:48 PM
Security Audit — agent-trust-hub — background-grid-webgl