auto-rig
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill defines tools that fetch 3D models and images from user-provided URLs for rigging and generation tasks.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external sources, creating a potential surface for indirect prompt injection.\n
- Ingestion points: Data enters via the
glb_url,image_url, andpromptparameters inSKILL.md.\n - Boundary markers: The instructions lack specific delimiters or warnings to ignore instructions embedded in fetched content.\n
- Capability inventory: The skill uses tools to perform network operations and generative tasks on the ingested data.\n
- Sanitization: There are no sanitization or verification steps defined for the external resources.
Audit Metadata