generative-art
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and review user-supplied generative art code, which establishes a potential surface for indirect prompt injection if malicious instructions are embedded in the data being analyzed.
- Ingestion points: User-provided art code and requests for diagnosis/review as instructed in
SKILL.md. - Boundary markers: Absent; there are no explicit delimiters to isolate user-provided code from the agent's instructions.
- Capability inventory: The skill provides templates for browser-based JavaScript (p5.js) and fragment shaders (GLSL). No sensitive file system, network exfiltration, or shell execution capabilities were identified.
- Sanitization: None identified; user input is processed based on the guidelines in
references/validations.mdwithout specific sanitization for prompt injection patterns. - [SAFE]: All provided code examples in
references/patterns.mdandreferences/sharp_edges.mdutilize standard, non-malicious creative coding libraries and patterns. Mentions of external libraries likeethersandopentype.jsin comments are for educational purposes and do not involve automated installation or execution.
Audit Metadata