theme-factory
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill package consists exclusively of static markdown and text files defining visual styles. There is no executable code, shell script, or binary included, which eliminates the possibility of unauthorized command execution.
- [SAFE]: A comprehensive scan for obfuscation techniques, including Base64 encoding, zero-width characters, and homoglyphs, found no evidence of hidden malicious payloads or URLs.
- [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection through the 'Create your Own Theme' feature, which processes user-provided descriptions. 1. Ingestion points: User-provided inputs for custom theme generation mentioned in SKILL.md. 2. Boundary markers: Not present in instructions. 3. Capability inventory: The skill allows the agent to read local theme files and apply formatting to documents. 4. Sanitization: No input validation is specified. This surface is evaluated as safe because the capability is limited to aesthetic styling and requires user confirmation.
Audit Metadata