web3d-animation
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npxto fetch and execute@gltf-transform/clifrom the npm registry. This is an industry-standard utility for glTF asset processing and is considered a safe source.- [COMMAND_EXECUTION]: Instructs the agent to execute shell commands usingnpxto perform model inspection and validation checks on 3D assets.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external 3D model files (glTF/GLB). Ingestion points: Files are parsed viagltf-transformto read animation names, joint counts, and morph targets. Boundary markers: The instructions do not define specific delimiters for asset-provided strings. Capability inventory: Includes shell command execution (npx) and network interaction with 3D generation APIs (Meshy/Tripo). Sanitization: Employs the@gltf-transform/cli validatecommand to ensure asset integrity and catch structural errors.- [SAFE]: All referenced external tools and services, including three.js, Meshy, Tripo, and Adobe Mixamo, are established and reputable providers in the 3D development ecosystem. The code patterns provided for WebGPU and React Three Fiber follow standard development practices.
Audit Metadata