NYC

vr-avatar-engineer

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [General] (SAFE): No evidence of malicious behavior, prompt injection, or data exfiltration found in the instructions or metadata.
  • [Code Snippets] (SAFE): The Swift, C#, and HLSL code examples are functional, industry-standard patterns for VR development and do not contain hidden malicious logic.
  • [Indirect Prompt Injection] (LOW): The use of WebFetch and Firecrawl tools to ingest external documentation creates a potential surface for indirect prompt injection from external websites. However, this is a known risk inherent to web-research capabilities and no specific exploitation patterns are present in the skill itself.
  • [Tool Usage] (SAFE): The inclusion of Bash and web-search tools is consistent with the stated purpose of research and development for cross-platform VR systems.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:04 PM