pixijs-custom-rendering
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill documents that PixiJS v8 uses
new Functionfor synchronizing Uniform Buffer Objects (UBOs) for performance reasons. It correctly identifies that this behavior may conflict with strict Content Security Policies (CSP) and instructs users to importpixi.js/unsafe-evalto enable a fallback synchronization path that avoids dynamic code generation. - [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for ingesting external data such as shader sources (GLSL/WGSL) and texture assets, creating an attack surface for indirect prompt injection.
- Ingestion points: Shader source strings (
vertexSrc,fragmentSrc,wgslSourceinSKILL.md) and external texture assets loaded viaAssets.load(). - Boundary markers: The instructions do not define boundary markers or "ignore instructions" blocks for shader code interpolation.
- Capability inventory: The skill allows for GPU rendering, uniform updates, and custom batcher logic. It does not provide access to sensitive files or arbitrary network calls.
- Sanitization: No sanitization or validation of the shader source strings is performed before they are passed to the PixiJS
Shader.fromorFilter.frommethods.
Audit Metadata