skills/vm0-ai/vm0-skills/tripo/Gen Agent Trust Hub

tripo

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses curl and jq to interact with the Tripo 3D API for task submission, status polling, and account management.
  • [EXTERNAL_DOWNLOADS]: Downloads generated 3D assets (GLB, FBX, USDZ) and rendered images from the Tripo 3D platform.
  • [PROMPT_INJECTION]: The skill processes user-supplied text and images as inputs for API generation tasks. Ingestion points: User-defined text prompts and file paths for image uploads. Boundary markers: No delimiters or safety instructions are provided to separate user data from the command context. Capability inventory: Network access via curl and local file access to /tmp for processing uploads. Sanitization: No explicit sanitization or escaping of user-provided strings is implemented in the command templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 01:52 AM
Security Audit — agent-trust-hub — tripo