algorithmic-art

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's HTML viewer template fetches the p5.js library from cdnjs.cloudflare.com. This is a well-known and trusted service for hosting web libraries.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect injection surface as it processes user-supplied aesthetic instructions to generate code. Evidence chain:
  • Ingestion points: User-provided creative prompts and instructions processed in SKILL.md.
  • Boundary markers: The skill lacks explicit markers or delimiters to isolate user instructions from the generation logic.
  • Capability inventory: The skill generates and executes JavaScript code within an interactive HTML artifact viewer.
  • Sanitization: No specific sanitization or validation logic is defined for the user-supplied conceptual inputs.
  • [DYNAMIC_EXECUTION]: The skill generates interactive JavaScript code (p5.js) based on an 'algorithmic philosophy' derived from user requests. This generation is contained within a restricted HTML template provided by the skill, which enforces a specific structure, parameters, and branding.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:09 AM
Security Audit — agent-trust-hub — algorithmic-art