pixijs-custom-rendering

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill documents that PixiJS v8 uses new Function for synchronizing Uniform Buffer Objects (UBOs) for performance reasons. It correctly identifies that this behavior may conflict with strict Content Security Policies (CSP) and instructs users to import pixi.js/unsafe-eval to enable a fallback synchronization path that avoids dynamic code generation.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for ingesting external data such as shader sources (GLSL/WGSL) and texture assets, creating an attack surface for indirect prompt injection.
  • Ingestion points: Shader source strings (vertexSrc, fragmentSrc, wgslSource in SKILL.md) and external texture assets loaded via Assets.load().
  • Boundary markers: The instructions do not define boundary markers or "ignore instructions" blocks for shader code interpolation.
  • Capability inventory: The skill allows for GPU rendering, uniform updates, and custom batcher logic. It does not provide access to sensitive files or arbitrary network calls.
  • Sanitization: No sanitization or validation of the shader source strings is performed before they are passed to the PixiJS Shader.from or Filter.from methods.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 03:58 PM