theme-factory

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: A thorough review of the skill instructions and the 10 included theme definitions found no evidence of malicious code, data exfiltration, or unauthorized persistence mechanisms. The skill's operations are limited to reading local markdown files and applying visual settings.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to generate custom themes based on user-provided descriptions, which creates a potential surface for indirect prompt injection. However, this is considered safe due to the skill's limited capabilities and the inclusion of a review step before applying generated themes.
  • Ingestion points: User-provided input for custom theme creation in SKILL.md.
  • Boundary markers: None identified.
  • Capability inventory: File reading from the local 'themes/' directory and modification of artifact presentation properties (colors and fonts).
  • Sanitization: No explicit sanitization or filtering of user input was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — theme-factory