meshy-3d-generation
Pass
Audited by Gen Agent Trust Hub on May 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses standard shell commands to detect environment variables and search for existing API keys in sensitive shell configuration files such as .bashrc and .zshrc.
- [COMMAND_EXECUTION]: It includes instructions to persist user-provided API keys by appending them to shell configuration profiles for use in future sessions.
- [EXTERNAL_DOWNLOADS]: The skill downloads generated 3D model files and thumbnails from the vendor's official asset delivery network (assets.meshy.ai).
- [COMMAND_EXECUTION]: It instructs the agent to create and execute local Python scripts to manage the asynchronous generation lifecycle (creation, polling, and downloading).
- [SAFE]: All network operations are directed at the official Meshy API domain (api.meshy.ai) for intended functionality such as credit balance checks and task processing.
Audit Metadata