theme-factory
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided artifacts (slides, docs, HTML) and theme files to apply styling. This creates a potential surface for indirect prompt injection from untrusted artifact content.
- Ingestion points: Reads local theme files and user-provided artifact files as described in
SKILL.md. - Boundary markers: None identified in the prompt instructions to isolate artifact content from instructions.
- Capability inventory: The agent is authorized to read and write to the filesystem to modify artifacts (described in
SKILL.md). - Sanitization: No specific sanitization of input artifact content is defined.
- [METADATA_POISONING]: There is a minor metadata inconsistency between the license specified in the plugin configuration
plugin.json(MIT) and theLICENSE.txtfile (Apache 2.0), though this does not impact security. - [SAFE]: The skill's primary functionality is limited to visual styling and design. All included theme files contain standard design properties (hex codes and font names) without executable logic. The author is a recognized entity, and references to external repositories point to official sources.
Audit Metadata