theme-factory

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a repository for visual design templates. All provided files are either markdown documentation or a standard Apache 2.0 license. There are no executable scripts, hardcoded credentials, or external network requests identified in the skill content.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to style external artifacts such as documents and slide decks. 1. Ingestion points: Untrusted external documents/slides provided by the user. 2. Boundary markers: None present. 3. Capability inventory: The skill is limited to applying font choices and color hex codes to artifacts. 4. Sanitization: No explicit sanitization of artifact content. The risk is categorized as safe because the skill's capabilities are restricted to cosmetic visual changes and it includes a user verification step for custom-generated themes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:22 PM
Security Audit — agent-trust-hub — theme-factory