theme-factory

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided artifacts (slides, docs, HTML) and theme files to apply styling. This creates a potential surface for indirect prompt injection from untrusted artifact content.
  • Ingestion points: Reads local theme files and user-provided artifact files as described in SKILL.md.
  • Boundary markers: None identified in the prompt instructions to isolate artifact content from instructions.
  • Capability inventory: The agent is authorized to read and write to the filesystem to modify artifacts (described in SKILL.md).
  • Sanitization: No specific sanitization of input artifact content is defined.
  • [METADATA_POISONING]: There is a minor metadata inconsistency between the license specified in the plugin configuration plugin.json (MIT) and the LICENSE.txt file (Apache 2.0), though this does not impact security.
  • [SAFE]: The skill's primary functionality is limited to visual styling and design. All included theme files contain standard design properties (hex codes and font names) without executable logic. The author is a recognized entity, and references to external repositories point to official sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:37 PM
Security Audit — agent-trust-hub — theme-factory