typegpu

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing official library components and dependencies from the npm registry, including 'typegpu', 'unplugin-typegpu', and utility packages like '@typegpu/noise' and '@typegpu/sdf'.\n- [REMOTE_CODE_EXECUTION]: Documentation describes the use of the 'npx typegpu@latest' command to scaffold and enhance projects, which executes the vendor's CLI tool directly from the npm registry.\n- [DYNAMIC_EXECUTION]: The library's core functionality involves transpiling TypeScript code blocks into WebGPU Shading Language (WGSL) at runtime for GPU execution, which is an intended and documented behavior of the framework.\n- [INDIRECT_PROMPT_INJECTION]: As a development tool, the skill processes code and external data (e.g., 3D models) as input for shader generation.\n
  • Ingestion points: User-authored 'use gpu' code blocks and external model files (OBJ/GLTF) loaded via '@loaders.gl' as described in 'references/pipelines.md'.\n
  • Boundary markers: Relies on structural API patterns and 'use gpu' directives to delimit shader logic.\n
  • Capability inventory: The skill is scoped to GPU buffer operations and rendering; it lacks arbitrary file system writes or unauthorized network access.\n
  • Sanitization: Uses schema-based validation and internal transpilation to process external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:17 AM
Security Audit — agent-trust-hub — typegpu