web3d-animation

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx to fetch and execute @gltf-transform/cli from the npm registry. This is an industry-standard utility for glTF asset processing and is considered a safe source.- [COMMAND_EXECUTION]: Instructs the agent to execute shell commands using npx to perform model inspection and validation checks on 3D assets.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external 3D model files (glTF/GLB). Ingestion points: Files are parsed via gltf-transform to read animation names, joint counts, and morph targets. Boundary markers: The instructions do not define specific delimiters for asset-provided strings. Capability inventory: Includes shell command execution (npx) and network interaction with 3D generation APIs (Meshy/Tripo). Sanitization: Employs the @gltf-transform/cli validate command to ensure asset integrity and catch structural errors.- [SAFE]: All referenced external tools and services, including three.js, Meshy, Tripo, and Adobe Mixamo, are established and reputable providers in the 3D development ecosystem. The code patterns provided for WebGPU and React Three Fiber follow standard development practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 11:56 PM
Security Audit — agent-trust-hub — web3d-animation