r3f-v10-webgpu-hooks

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The file references/alpha-5.md contains a shell command template (node --input-type=module) that uses a heredoc to execute a JavaScript diagnostic snippet intended for verifying object disposal logic.
  • [DYNAMIC_EXECUTION]: The diagnostic script in references/alpha-5.md demonstrates the dynamic execution of JavaScript logic via the Node.js CLI to verify library-specific object disposal behavior. The logic is benign and used for development verification.
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to read and inspect local library files in the project workspace (e.g., index.d.ts and index.mjs) to understand alpha-version APIs. Evidence Chain: 1. Ingestion points: SKILL.md (instructions to inspect dist/webgpu/). 2. Boundary markers: Absent. 3. Capability inventory: The agent reads workspace files and generates React code. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:07 PM
Security Audit — agent-trust-hub — r3f-v10-webgpu-hooks