shader-dev
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill content is entirely educational and functional, consisting of Markdown-based documentation and GLSL/JavaScript code snippets. A thorough scan of the included files revealed no suspicious activity, hardcoded credentials, or hidden malicious logic.
- [INDIRECT_PROMPT_INJECTION]: The skill defines an interaction model where the agent synthesizes executable code (HTML/JavaScript) based on user-provided descriptions.
- Ingestion points: User input enters the agent context via the
$ARGUMENTSvariable inSKILL.mdto trigger specific shader assemblies. - Boundary markers: Absent; the instructions do not specify the use of delimiters or 'ignore' instructions for user-supplied requirements.
- Capability inventory: The skill allows the agent to generate and structure complex code that can be executed in a browser environment.
- Sanitization: Absent; the skill relies on the agent's internal safety guardrails to ensure that user requests do not lead to the generation of malicious scripts (e.g., XSS) in the output.
Audit Metadata