skills/erphq/skills/cream-theme/Gen Agent Trust Hub

cream-theme

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill instructs the agent to use credentials stored at ~/.build-host/credentials.json for authentication. This is a sensitive file path; however, it is the primary intended mechanism for the skill to interact with the build.host API. The skill contains explicit safety rules prohibiting the agent from printing these secrets or including them in chat logs.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes untrusted local data.
  • Ingestion points: Project directory and git repository files (SKILL.md).
  • Boundary markers: None identified in the instructions.
  • Capability inventory: Local file modifications and network deployment via build.host API.
  • Sanitization: None identified; the skill directly reads UI and constraints from project files to inform its actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 04:43 PM
Security Audit — agent-trust-hub — cream-theme