pp-sculptok

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the SculptOK CLI using npx from the @mvanhorn NPM scope and go install from the mvanhorn GitHub repository. These are the primary methods for obtaining the necessary binaries.
  • [COMMAND_EXECUTION]: The skill is designed to execute the sculptok-pp-cli tool for image-to-3D conversion and local database management.
  • [DATA_EXFILTRATION]: The underlying CLI tool supports an optional --deliver webhook:<url> flag to send output to external endpoints and a feedback mechanism that can optionally send logs to a user-defined SCULPTOK_FEEDBACK_ENDPOINT. These are documented features of the tool.
  • [PROMPT_INJECTION]: The which command accepts natural-language capability queries, representing a surface for indirect prompt injection where untrusted data could influence command selection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 03:01 AM
Security Audit — agent-trust-hub — pp-sculptok