threejs-loaders
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches Draco decoder binaries from Google's gstatic.com CDN to enable mesh compression support.
- [EXTERNAL_DOWNLOADS]: The skill downloads KTX2/Basis transcoder scripts from the JSDelivr CDN, targeting specific versions of the Three.js library.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill provides an example of a URL modifier for CDN integration using a reserved documentation domain (example.com).
- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates ingestion of external 3D models and textures. However, as the skill lacks capabilities for shell execution, local file writes, or credential access, the risk is negligible.
Audit Metadata