dream-loop
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes standard local shell commands to support its visual build and review workflow.
- The instructions direct the agent to host the 3D scene locally using
python3 -m http.serverto allow for automated browser screenshots. - The procedure uses ImageMagick's
convertutility to stitch concept art and rendered screenshots together for side-by-side analysis. - [INDIRECT_PROMPT_INJECTION]: The skill architecture processes user-provided content and external assets, which represents a surface for indirect instructions.
- Ingestion points: The agent processes user descriptions at Stage 1 and may optionally pull external models, textures, or HDRIs during Stage 4.
- Boundary markers: The skill does not currently implement explicit boundary markers or "ignore instructions" warnings for the ingested data.
- Capability inventory: The skill has access to local command execution (Python, ImageMagick), browser automation, and the ability to delegate tasks to subagents.
- Sanitization: No specific sanitization or filtering logic is prescribed for the external inputs before they are incorporated into the prompt or used to influence agent behavior.
Audit Metadata