skills/sfrmrc/skills/unicorn-studio/Gen Agent Trust Hub

unicorn-studio

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill mentions using the Unicorn Studio SDK via UMD from jsDelivr and fetching scene configurations from external URLs (e.g., data-us-project-src). These are standard integration methods for the service described and do not involve suspicious execution patterns.
  • [COMMAND_EXECUTION]: There are no shell commands, scripts, or system-level operations included in the skill instructions or metadata.
  • [DATA_EXFILTRATION]: No sensitive file paths, environment variables, or credentials are accessed or transmitted by the skill.
  • [PROMPT_INJECTION]: The instructions are focused on providing technical guidance for web development and do not attempt to override agent safety protocols or system instructions.
  • [DYNAMIC_EXECUTION]: The provided demo (demo/index.html) uses standard client-side JavaScript for Canvas rendering and event handling without the use of eval(), exec(), or unsafe deserialization.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 01:36 PM
Security Audit — agent-trust-hub — unicorn-studio