asset-pipeline

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external media files which serve as ingestion points for untrusted data, though the risk is inherent to the skill's primary purpose.
  • Ingestion points: Processes user-provided image files (e.g., raw.png) and 3D models (e.g., unit.glb) in SKILL.md.
  • Capability inventory: The skill uses the um CLI tool to perform file system operations and network requests to remote services.
  • Boundary markers: The instructions do not specify delimiters or safety warnings for the agent when handling potentially malicious file content or metadata.
  • Sanitization: No explicit sanitization or validation of input files is mentioned prior to processing by the toolchain.
  • [EXTERNAL_DOWNLOADS]: The skill documents dependencies on external third-party software that must be present on the execution environment.
  • Software requirements: References the need for Blender, ImageMagick (magick), and DirectXTex (texconv) for rendering and conversion tasks.
  • [COMMAND_EXECUTION]: The skill relies on shell command execution to perform asset processing.
  • Command usage: Extensively uses the um utility with various subcommands (sprite, render3d, fal) to manipulate local files and interact with remote APIs for 3D remeshing.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 05:17 PM
Security Audit — agent-trust-hub — asset-pipeline