applying-themes

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill allows for the generation of custom themes based on user-provided descriptions, creating a surface for potential injection attacks.
  • Ingestion points: The 'Create your Own Theme' section in SKILL.md directs the agent to generate new themes based on descriptions provided by the user at runtime.
  • Boundary markers: Absent. The instructions do not include delimiters or specific warnings to the agent to disregard instructions that might be embedded within the user's theme description.
  • Capability inventory: The skill is designed to modify visual artifacts, including slide decks, documents, reports, and HTML landing pages.
  • Sanitization: Absent. There is no mention of validating, filtering, or escaping the user's input before the agent processes it to generate the theme attributes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — applying-themes