Back to skill

Security audit

Image To 3d Asset

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for creating 3D assets through disclosed Runware model calls, with no hidden installer, persistence, or destructive behavior found.

Install only if you are comfortable sending the chosen images or text prompts to Runware-compatible model tools and potentially incurring provider usage costs. Avoid using sensitive private images unless that provider workflow is acceptable for your use case.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
- **Default: Rodin Gen-2** (`hyper3d:rodin@gen-2`). Production-ready meshes, the richest control surface (mesh mode, polygon budget, HighPack 4K, T/A pose, PBR vs baked). Best general pick.
- **Cheaper/faster alt: Meshy-6** (`meshy:meshy@6`). Clean geometry, low-poly and symmetry control, image-enhancement toggle. Good for volume and game assets.
- **Other strong picks: Hunyuan 3D 3.1 Pro** (`tencent:hunyuan-3d@3.1-pro`) and **Tripo 3D v3.1** (`tripo:v3.1@0`). Both do image-to-3D and text-to-3D, with Tripo the lowest-cost tier.
- Confirm the live model + its schema via `runware-models` + `runware-run` before calling. Control fields differ per model, so never copy one model's `settings` onto another without checking.

## Workflow
Confidence
75% confidence
Finding
without checking

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.