theme-factory

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill package consists entirely of Markdown-based theme definitions and usage instructions. No executable scripts, source code, or binary files are provided within the package.\n- [PROMPT_INJECTION]: The skill's functionality involves processing external data (artifacts and custom theme descriptions), which creates a surface for indirect prompt injection.\n
  • Ingestion points: External slide decks, documents, and landing pages being styled, along with user-provided descriptions for custom themes (SKILL.md).\n
  • Boundary markers: None. The skill does not provide instructions to the agent on how to separate or ignore instructions that may be embedded in the processed artifacts.\n
  • Capability inventory: Reading and modifying external documents and artifacts as described in the application process (SKILL.md).\n
  • Sanitization: None. No mechanisms for validating or sanitizing the content of the ingested artifacts are mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 07:46 AM
Security Audit — agent-trust-hub — theme-factory