theme-factory

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's documentation references an installation command and a source repository associated with a well-known organization. These references are used for attribution and setup and do not involve runtime downloads of executable code from untrusted sources.\n- [PROMPT_INJECTION]: The skill provides functionality to generate custom themes based on user-supplied descriptions and names. This creates a surface for indirect prompt injection, as the agent is instructed to use these inputs to define the visual identity and then apply it to artifacts. Maliciously crafted inputs could potentially be used to inject instructions that alter the agent's subsequent processing of the artifact.\n
  • Ingestion points: User-provided theme names and descriptions used in the custom theme generation process (SKILL.md).\n
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are used when the agent processes the generated theme content.\n
  • Capability inventory: The skill has the capability to read local theme specifications and modify the visual styling of user artifacts.\n
  • Sanitization: There is no mention of sanitizing or validating user-provided strings before they are used to define theme parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 09:37 AM
Security Audit — agent-trust-hub — theme-factory