generative-art

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and review user-supplied generative art code, which establishes a potential surface for indirect prompt injection if malicious instructions are embedded in the data being analyzed.
  • Ingestion points: User-provided art code and requests for diagnosis/review as instructed in SKILL.md.
  • Boundary markers: Absent; there are no explicit delimiters to isolate user-provided code from the agent's instructions.
  • Capability inventory: The skill provides templates for browser-based JavaScript (p5.js) and fragment shaders (GLSL). No sensitive file system, network exfiltration, or shell execution capabilities were identified.
  • Sanitization: None identified; user input is processed based on the guidelines in references/validations.md without specific sanitization for prompt injection patterns.
  • [SAFE]: All provided code examples in references/patterns.md and references/sharp_edges.md utilize standard, non-malicious creative coding libraries and patterns. Mentions of external libraries like ethers and opentype.js in comments are for educational purposes and do not involve automated installation or execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:06 PM
Security Audit — agent-trust-hub — generative-art