build-threejs-scroll-worlds

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill focuses on providing best practices for 3D web development, including scene graph management, performance budgeting, and accessibility. No evidence of prompt injection, credential harvesting, or persistence mechanisms was found.
  • [EXTERNAL_DOWNLOADS]: The skill references a public GitHub project (github.com/oso95/scroll-world) for structural intake and budget references. This is a well-known service and the reference is documented as a structural guide, presenting no security risk.
  • [INDIRECT_PROMPT_INJECTION]: The instructions ask the agent to inspect user-provided reference scenes or models to extract geometry and material properties. While this is an input surface for external data, the risk is minimal given the technical nature of the task and the lack of instructions to execute content embedded in those models.
  • [NO_CODE]: The provided code in the references/ directory, such as scroll-conductor.js, is utility-focused JavaScript for handling native scroll normalization and lacks any malicious functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 10:00 AM
Security Audit — agent-trust-hub — build-threejs-scroll-worlds