reference-to-3d

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface where untrusted user-supplied image data is processed and used to inform the generation of Blender Python code.\n
  • Ingestion points: Reference images are analyzed by template_analyzer.py and silhouette_validator.py as part of the reconstruction workflow.\n
  • Boundary markers: No explicit delimiters or instructions are used to distinguish extracted visual data from the agent's operational instructions.\n
  • Capability inventory: The skill generates Blender Python scripts for execution via mcp__blender__execute_blender_code and utilizes the bash tool for local script execution.\n
  • Sanitization: The skill does not perform sanitization or verification of the content within the ingested images before using the derived data in code generation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 08:28 PM
Security Audit — agent-trust-hub — reference-to-3d