theme-factory

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill operates by ingesting and extracting structure from external artifacts, creating a surface for indirect prompt injection.\n
  • Ingestion points: Target artifacts including slides, documents, reports, and HTML pages mentioned in Purpose and Core Workflows.\n
  • Boundary markers: The instructions lack specific boundary markers or 'ignore' commands for content processed from these artifacts.\n
  • Capability inventory: While the skill itself contains no tools, it instructs the agent to perform structure extraction and layout adjustments on user-provided artifacts.\n
  • Sanitization: No content sanitization or validation steps are included in the workflows.\n- [NO_CODE]: The skill consists entirely of markdown documentation and workflows; it does not include any executable scripts, binaries, or command-line instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 08:32 AM
Security Audit — agent-trust-hub — theme-factory