algorithmic-art
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The "DEDUCING THE CONCEPTUAL SEED" section instructs the agent to embed "subtle, niche reference[s]" invisibly within the generated algorithm, which is a form of behavioral steering that encourages non-transparent output.- [EXTERNAL_DOWNLOADS]: The skill correctly uses well-known services (cdnjs.cloudflare.com for the p5.js library and fonts.googleapis.com for typography). These are recognized as safe, established infrastructure providers.- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided inputs to generate an "algorithmic philosophy" and then implements that philosophy as JavaScript code, creating an attack surface for indirect injection. * Ingestion points: User art requests and conceptual seeds enter the agent's context (SKILL.md). * Boundary markers: There are no explicit delimiters or instructions provided to isolate the user-supplied data from the code generation logic. * Capability inventory: The skill generates and executes JavaScript code within an interactive artifact viewer (templates/viewer.html). * Sanitization: The instructions do not define any validation or sanitization requirements for the user input before it is used to generate code.- [DYNAMIC_EXECUTION]: The core functionality of the skill is the runtime generation and execution of JavaScript code to produce interactive art, which is a form of dynamic code generation.
Audit Metadata