build-threejs-scroll-worlds

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious behavior, prompt injections, or unauthorized data access patterns were identified. The instructions are consistent with the stated purpose of building 3D scrollytelling websites.
  • [EXTERNAL_DOWNLOADS]: The skill references an external GitHub repository (github.com/oso95/scroll-world) as a structural reference. This is a well-known service and the reference is used neutrally for educational purposes.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection by design. * Ingestion points: Processes user-provided 3D models, textures, and scene data (e.g., SKILL.md, references/world-bible.md). * Boundary markers: Not explicitly defined for asset metadata. * Capability inventory: Code generation (JavaScript/Three.js), DOM manipulation, and asset loading. * Sanitization: Relies on standard Three.js loaders.
  • [OBFUSCATION]: The file demo/secret-pathways-assets/fonts.css contains Base64 encoded font data (woff2). This is a standard method for embedding web fonts and does not contain executable malicious commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:30 AM
Security Audit — agent-trust-hub — build-threejs-scroll-worlds