skills/pmndrs/xr/pmndrs-xr/Gen Agent Trust Hub

pmndrs-xr

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied React code and 3D assets to build interactive environments. It incorporates spatial tracking data from XR hardware during automated validation processes.
  • Ingestion points: React components, GLTF models, and XR input state (e.g., references/docs/tutorials/anchors.md).
  • Boundary markers: Not explicitly specified for development-time data processing.
  • Capability inventory: Uses npm for package installation and vitexec for automated validation walkthroughs (SKILL.md, references/validation.md).
  • Sanitization: Standard development workflow; no specific content sanitization is required for this use case.
  • [EXTERNAL_DOWNLOADS]: The skill references standard assets and libraries from official vendor repositories and trusted CDNs.
  • Evidence: References to @pmndrs/xr and @react-three/handle packages, and assets served from cdn.jsdelivr.net/npm/@webxr-input-profiles/assets.
  • [COMMAND_EXECUTION]: Instructions guide the agent through routine development tasks using expected CLI tools.
  • Evidence: Use of npm install for library management and vitexec for local script execution and validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:21 PM
Security Audit — agent-trust-hub — pmndrs-xr