theme-factory
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, hardcoded secrets, or suspicious network activities were detected. The instructions focus on aesthetic styling and professional theme application.
- [NO_CODE]: The skill package is composed entirely of Markdown configuration files and instructional text. No executable scripts, binaries, or automated tasks are present, which significantly limits the potential for unauthorized code execution.
- [PROMPT_INJECTION]: The skill processes untrusted user-defined inputs for theme generation and reads existing artifacts, creating a surface for indirect prompt injection. * Ingestion points: User-provided theme descriptions and existing document/slide content. * Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present. * Capability inventory: Reading theme configuration files and modifying user artifacts. * Sanitization: No content validation or escaping is specified for the input data.
Audit Metadata