theme-factory

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves as a static library of theme configurations (hex codes and fonts). No executable code or scripts are included in the distribution.
  • [DATA_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or network operations were identified within the skill files.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform any remote package installations or script executions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided artifacts for styling, which creates a surface for indirect prompt injection.
  • Ingestion points: User-provided artifacts (slides, documents) as specified in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: The skill only applies hex codes and fonts; no subprocesses, network calls, or dangerous file operations are present in any files.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:57 PM
Security Audit — agent-trust-hub — theme-factory