theme-factory
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as a static library of theme configurations (hex codes and fonts). No executable code or scripts are included in the distribution.
- [DATA_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or network operations were identified within the skill files.
- [REMOTE_CODE_EXECUTION]: The skill does not perform any remote package installations or script executions.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided artifacts for styling, which creates a surface for indirect prompt injection.
- Ingestion points: User-provided artifacts (slides, documents) as specified in
SKILL.md. - Boundary markers: Absent.
- Capability inventory: The skill only applies hex codes and fonts; no subprocesses, network calls, or dangerous file operations are present in any files.
- Sanitization: Absent.
Audit Metadata