dream-loop

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes standard local shell commands to support its visual build and review workflow.
  • The instructions direct the agent to host the 3D scene locally using python3 -m http.server to allow for automated browser screenshots.
  • The procedure uses ImageMagick's convert utility to stitch concept art and rendered screenshots together for side-by-side analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill architecture processes user-provided content and external assets, which represents a surface for indirect instructions.
  • Ingestion points: The agent processes user descriptions at Stage 1 and may optionally pull external models, textures, or HDRIs during Stage 4.
  • Boundary markers: The skill does not currently implement explicit boundary markers or "ignore instructions" warnings for the ingested data.
  • Capability inventory: The skill has access to local command execution (Python, ImageMagick), browser automation, and the ability to delegate tasks to subagents.
  • Sanitization: No specific sanitization or filtering logic is prescribed for the external inputs before they are incorporated into the prompt or used to influence agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 04:02 PM