web-three-r3f — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited web-three-r3f (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 2 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Three.js, React Three Fiber, Drei, Canvas/createRoot lifecycle, loaders, GLTF, useFrame, disposal, SSR/client boundaries, DPR, and browser proof.
Use this skill as a compact router plus domain checklist. Load references only when the current task matches their condition. Do not cite local scrape paths, machine cache paths, or hidden source locations. Verify API details against the target repo's installed package versions before editing.
local design tokens, accessibility policy, and existing motion patterns.
excerpts.
bundled notes are version-sensitive.
<!-- skill-resources:start -->
references/r3f-scene-lifecycle.md - Canvas/createRoot and scene lifecycle. Read for Canvas props, custom root ownership, SSR/client boundaries, and resize.references/asset-loaders-and-fallbacks.md - GLTF/texture loaders and fallbacks. Read for useGLTF/useTexture, Suspense, decoder paths, and asset errors.references/three-disposal-performance.md - Three.js disposal and performance guide. Read for renderer cleanup, render targets, materials, textures, DPR, frameloop, and profiling.references/interaction-and-event-boundaries.md - R3F interaction and event boundaries. Read when a Three/R3F scene handles pointer, keyboard, scroll, controls, raycasting, or HTML overlays.references/asset-pipeline-compression.md - 3D asset pipeline, compression, and loader policy. Read when loading GLTF/GLB, textures, Draco/Meshopt/KTX2 assets, or remote 3D content.references/docs-drei-gltf-use-gltf.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/docs-r3f-canvas.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/docs-r3f-pitfalls.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/docs-r3f-scaling-performance.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/docs-three-disposal.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/docs-r3f-introduction.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/docs-three-creating-a-scene.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/r3f-field-guide.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/index.md - Complete reference inventory and routing summary.references/source-ledger.md - Source list, checked date, and copy policy.references/provenance.json - Machine-readable source and local-resource metadata.scripts/audit.mjs - Self-contained audit CLI; run doctor before scan when setup is unclear.assets/templates/web-three-r3f-audit-report.md - Audit response/report template.assets/templates/web-three-r3f-review-checklist.md - Manual review checklist.assets/examples/web-three-r3f-starter.tsx - Starter fixture/example for this skill.evals/trigger-queries.json - Trigger/near-miss eval set for description tuning.evals/evals.json - Task-quality evals with assertions.<!-- skill-resources:end -->
node scripts/audit.mjs doctor --root . --format json
node scripts/audit.mjs scan --root . --format markdown
node scripts/audit.mjs scan --root . --format json --output web-three-r3f-audit.jsonTreat script findings as leads. Verify every finding against current code before changing behavior or reporting it as valid.
Before finalizing, run the repo's focused validation command, this skill's audit CLI when relevant, and any browser/device/manual proof required by the changed surface. Report commands run, findings fixed, findings skipped with reasons, and residual risk.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.