unicorn-studio
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill mentions using the Unicorn Studio SDK via UMD from jsDelivr and fetching scene configurations from external URLs (e.g.,
data-us-project-src). These are standard integration methods for the service described and do not involve suspicious execution patterns. - [COMMAND_EXECUTION]: There are no shell commands, scripts, or system-level operations included in the skill instructions or metadata.
- [DATA_EXFILTRATION]: No sensitive file paths, environment variables, or credentials are accessed or transmitted by the skill.
- [PROMPT_INJECTION]: The instructions are focused on providing technical guidance for web development and do not attempt to override agent safety protocols or system instructions.
- [DYNAMIC_EXECUTION]: The provided demo (demo/index.html) uses standard client-side JavaScript for Canvas rendering and event handling without the use of
eval(),exec(), or unsafe deserialization.
Audit Metadata