webgl-depth-gallery
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches the Three.js library from the JSDelivr CDN (
https://cdn.jsdelivr.net/npm/three@0.160.0/build/three.module.js) inexample.html. JSDelivr is a well-known service for delivering open-source packages, and this usage is standard for WebGL-based artifacts. - [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection as it ingests user design queries to generate code artifacts.
- Ingestion points: User input triggers defined in
SKILL.mdand theuseCasefield inopen-design.json. - Boundary markers: None explicitly defined in the provided file templates.
- Capability inventory: The skill is configured with the
fs:writecapability inopen-design.jsonto allow the agent to generate and save theindex.htmlfile. - Sanitization: The skill uses a fixed structural template in
example.html, which guides the agent to produce a predictable and safe interactive design rather than dynamically executing untrusted strings.
Audit Metadata