build-threejs-scroll-worlds
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill focuses on providing best practices for 3D web development, including scene graph management, performance budgeting, and accessibility. No evidence of prompt injection, credential harvesting, or persistence mechanisms was found.
- [EXTERNAL_DOWNLOADS]: The skill references a public GitHub project (
github.com/oso95/scroll-world) for structural intake and budget references. This is a well-known service and the reference is documented as a structural guide, presenting no security risk. - [INDIRECT_PROMPT_INJECTION]: The instructions ask the agent to inspect user-provided reference scenes or models to extract geometry and material properties. While this is an input surface for external data, the risk is minimal given the technical nature of the task and the lack of instructions to execute content embedded in those models.
- [NO_CODE]: The provided code in the
references/directory, such asscroll-conductor.js, is utility-focused JavaScript for handling native scroll normalization and lacks any malicious functionality.
Audit Metadata