skills/fine405/skills/app-icon-theme/Gen Agent Trust Hub

app-icon-theme

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to utilize the rg command for discovering theme modules within the skill's reference directory. This usage is confined to local file discovery and does not involve untrusted input or risky operations.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided theme descriptions and reference icons, creating a potential surface for indirect prompt injection during the prompt construction phase for image generation tools.\n
  • Ingestion points: User-defined semantic themes, material cues, and source icon images ingested via the SKILL.md workflow.\n
  • Boundary markers: The skill mandates 'identity invariants' and 'explicit exclusions' to ensure the agent ignores extraneous or malicious instructions in the input data.\n
  • Capability inventory: The skill uses file discovery commands (rg) and interacts with image generation tools.\n
  • Sanitization: Implements a 'theme quality gate' that scores identity recognition and craft, and specifically rejects outputs that use stereotypes or caricatures.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 03:18 AM
Security Audit — agent-trust-hub — app-icon-theme