r3f-v10-webgpu-hooks
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The file
references/alpha-5.mdcontains a shell command template (node --input-type=module) that uses a heredoc to execute a JavaScript diagnostic snippet intended for verifying object disposal logic. - [DYNAMIC_EXECUTION]: The diagnostic script in
references/alpha-5.mddemonstrates the dynamic execution of JavaScript logic via the Node.js CLI to verify library-specific object disposal behavior. The logic is benign and used for development verification. - [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to read and inspect local library files in the project workspace (e.g.,
index.d.tsandindex.mjs) to understand alpha-version APIs. Evidence Chain: 1. Ingestion points:SKILL.md(instructions to inspectdist/webgpu/). 2. Boundary markers: Absent. 3. Capability inventory: The agent reads workspace files and generates React code. 4. Sanitization: Absent.
Audit Metadata