tripo
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
curlandjqto interact with the Tripo 3D API for task submission, status polling, and account management. - [EXTERNAL_DOWNLOADS]: Downloads generated 3D assets (GLB, FBX, USDZ) and rendered images from the Tripo 3D platform.
- [PROMPT_INJECTION]: The skill processes user-supplied text and images as inputs for API generation tasks. Ingestion points: User-defined text prompts and file paths for image uploads. Boundary markers: No delimiters or safety instructions are provided to separate user data from the command context. Capability inventory: Network access via
curland local file access to/tmpfor processing uploads. Sanitization: No explicit sanitization or escaping of user-provided strings is implemented in the command templates.
Audit Metadata