add-3d-assets
Warn
Audited by Socket on Mar 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core behavior mostly matches the stated purpose of upgrading a Three.js game with 3D assets, and data flows appear to go to official providers rather than proxy exfiltration services. Risk is elevated by transitive skill loading, hidden behavior in local bundled scripts, external asset downloads, and execution of target-project npm scripts, but there is not enough evidence here for malicious intent.
Confidence: 85%Severity: 58%
Audit Metadata