usd-inspect-and-provenance
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a standard utility for auditing USD stages. All scripts are read-only and operate on user-supplied local files.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The instructions include security best practices, explicitly advising the user to record absolute paths only in local reports and to sanitize any data shared externally.
- [COMMAND_EXECUTION]: The skill uses Blender's bundled Python environment to execute a local inspection script. This is a standard and expected behavior for the described workflow.
- [INDIRECT_PROMPT_INJECTION]: While the skill ingests external USD data, it performs deterministic structural checks (mesh topology, transform finiteness) and outputs structured JSON metadata, which poses no significant risk of prompt injection.
Audit Metadata