theme-factory
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed entirely of markdown documentation and theme configuration files. No executable scripts (.py, .js, .sh), binaries, or obfuscated code blocks are present.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves processing external artifacts (such as slide decks or documents) and user-provided descriptions to apply or generate themes. This introduces a potential surface for indirect prompt injection if those external sources contain malicious instructions.
- Ingestion points: Contents of the artifacts provided for styling and the natural language descriptions used for custom theme generation.
- Boundary markers: Absent. The instructions do not specify the use of delimiters or warnings to ignore commands embedded within the artifacts.
- Capability inventory: Reading artifact content and applying stylistic modifications (colors/fonts).
- Sanitization: None mentioned in the instructions.
Audit Metadata