algorithmic-art

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The instructions mandate the agent to project a highly expert persona by repeatedly using specific phrases regarding craftsmanship and implementation quality (e.g., 'meticulously crafted', 'deep expertise'). This shapes the agent's descriptive behavior to emphasize quality and effort.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user requests to generate code-based art, which is then rendered as an interactive HTML artifact. This creates a surface where malicious user input could potentially be interpolated into the generated JavaScript code.
  • Ingestion points: Interprets 'user request' from SKILL.md to derive conceptual seeds and algorithmic implementation details.
  • Boundary markers: No explicit delimiters or 'ignore' instructions are provided to separate user-provided concepts from the generated code logic.
  • Capability inventory: The system generates standalone HTML/JS files using templates/viewer.html, allowing full browser-based code execution.
  • Sanitization: There is no requirement for sanitizing or validating user-supplied creative concepts before they are processed into the final code artifact.
  • [EXTERNAL_DOWNLOADS]: The skill's viewer template fetches the p5.js library from Cloudflare's public CDNJS repository at 'https://cdnjs.cloudflare.com/ajax/libs/p5.js/1.7.0/p5.min.js'. This is a neutral reference to a well-known service for hosting established open-source libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:00 PM
Security Audit — agent-trust-hub — algorithmic-art