webgl-depth-gallery

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches the Three.js library from the JSDelivr CDN (https://cdn.jsdelivr.net/npm/three@0.160.0/build/three.module.js) in example.html. JSDelivr is a well-known service for delivering open-source packages, and this usage is standard for WebGL-based artifacts.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection as it ingests user design queries to generate code artifacts.
  • Ingestion points: User input triggers defined in SKILL.md and the useCase field in open-design.json.
  • Boundary markers: None explicitly defined in the provided file templates.
  • Capability inventory: The skill is configured with the fs:write capability in open-design.json to allow the agent to generate and save the index.html file.
  • Sanitization: The skill uses a fixed structural template in example.html, which guides the agent to produce a predictable and safe interactive design rather than dynamically executing untrusted strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:20 AM
Security Audit — agent-trust-hub — webgl-depth-gallery