skills/grupous/gpus/theme-factory/Gen Agent Trust Hub

theme-factory

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill package consists exclusively of Markdown files containing theme definitions and usage instructions. It contains no executable scripts, binaries, or system configuration files.
  • [PROMPT_INJECTION]: The feature allowing for the creation of custom themes based on user-provided inputs introduces a standard indirect prompt injection surface. The agent generates theme instructions from untrusted input and subsequently processes those instructions to modify artifacts.
  • Ingestion points: User-provided descriptions and inputs for custom theme generation specified in SKILL.md.
  • Boundary markers: No delimiters or instructions are used to isolate user-supplied theme descriptions from the agent's internal logic.
  • Capability inventory: The agent is authorized to modify file content (slides, docs, HTML) according to theme parameters.
  • Sanitization: No validation or filtering is applied to user inputs or the resulting generated theme content.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 09:21 AM
Security Audit — agent-trust-hub — theme-factory