theatre-js

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and install official packages from the Theatre.js ecosystem, including @theatre/core, @theatre/studio, @theatre/react, and @theatre/r3f from the standard NPM registry.
  • [COMMAND_EXECUTION]: Provides standard command-line instructions for package management using npm and npx to set up the development environment and install the skill itself.
  • [SAFE]: All external resource links, including documentation, GitHub repositories, and community Discord servers, point to the official Theatre.js domain and verified community channels.
  • [SAFE]: Code examples follow security best practices, such as explicitly warning against including the Studio editor in production builds and demonstrating how to securely load pre-exported animation states.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 02:39 PM
Security Audit — agent-trust-hub — theatre-js