threejs-builder
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The skill imports and executes ES modules at runtime from the unpkg CDN (e.g. https://unpkg.com/three@0.160.0/build/three.module.js and https://unpkg.com/three@0.160.0/examples/jsm/controls/OrbitControls.js), which are fetched when the app runs and therefore constitute remote code execution that the skill depends on.
Audit Metadata