threejs-visual-systems
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructions for building 3D systems using standard Three.js libraries and development workflows. Analysis of the 10 threat categories confirms no security risks are present.
- [PROMPT_INJECTION]: No evidence of malicious prompt injection or instructions to bypass safety guardrails. The 'Fresh-Eyes Review' and 'Adversarial Self-Review' mentioned in the scorecard are design-quality techniques, not AI jailbreak attempts.
- [DATA_EXFILTRATION]: The skill does not access sensitive local files or hardcoded credentials. It mentions capturing screenshots and metrics for quality assessment, which is a local development activity.
- [COMMAND_EXECUTION]: While the skill mentions local tool execution (e.g., pnpm inspect:canvas), these are standard developer tools for the domain. There is no evidence of unauthorized or malicious shell command injection.
- [EXTERNAL_DOWNLOADS]: All external references target official documentation, local project paths, or the author's own 'Mint MCP' asset pipeline, with no signs of typosquatting or untrusted remote code execution.
Audit Metadata