three-js
Pass
Audited by Gen Agent Trust Hub on Feb 15, 2026
Risk Level: LOW
Full Analysis
- [PROMPT_INJECTION] (SAFE): No malicious override or bypass instructions were detected. The use of 'IMPORTANT' in the documentation is used for legitimate instructional clarity regarding the library's version (Vanilla vs React).
- [DATA_EXFILTRATION] (SAFE): The skill does not access sensitive files, environment variables, or perform any network requests.
- [REMOTE_CODE_EXECUTION] (SAFE): No remote scripts are downloaded or executed. The code snippets provided are static JavaScript examples for Three.js development.
- [COMMAND_EXECUTION] (SAFE): The skill contains no logic for executing shell commands or subprocesses.
- [EXTERNAL_DOWNLOADS] (SAFE): No external dependencies are fetched or installed during runtime. While the README mentions an installation command for the skill itself, the skill content is static.
Audit Metadata