spline-3d-integration

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches official Spline runtime and viewer libraries from https://unpkg.com. These are well-known services required for rendering 3D scenes.\n- [COMMAND_EXECUTION]: Includes instructions for installing official packages such as @splinetool/react-spline, @splinetool/vue-spline, and @splinetool/runtime through standard package managers.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided Spline scene URLs from https://prod.spline.design/ to generate integration code.\n
  • Ingestion points: Scene URLs are ingested through instructions in SKILL.md and the integration guides.\n
  • Boundary markers: Absent; the skill expects specific URL formats but does not use delimiters to isolate these inputs within generated code.\n
  • Capability inventory: The generated code is restricted to client-side WebGL and UI interactions. There are no subprocess calls, system file modifications, or privileged operations.\n
  • Sanitization: Absent; the skill relies on the standard structure of the Spline design platform URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 02:09 AM
Security Audit — agent-trust-hub — spline-3d-integration