theme-whatif
Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a style guide and template for visual generation tasks. Analysis of the instructions, metadata, and reference examples reveals no malicious intent or security vulnerabilities.
- [PROMPT_INJECTION]: While the document frequently uses the term 'CRITICAL', these headers are used to highlight essential design constraints and rendering rules (e.g., separating scene description from rendered text) rather than attempting to override the underlying AI's safety protocols or system instructions.
- [DATA_EXFILTRATION]: There are no commands or instructions that access sensitive files, environment variables, or perform network requests to external domains. The skill does not contain hardcoded credentials or API keys.
- [REMOTE_CODE_EXECUTION]: The skill consists of documentation and prompt templates. It does not include executable code, script installation commands, or references to external code repositories.
- [INDIRECT_PROMPT_INJECTION]: The skill provides structured rules for how a 'prompt-designer' should handle user content (e.g., placing text in a CONTENT block and descriptions in an INSTRUCTION block). These guidelines act as a form of sanitization to ensure proper rendering, rather than introducing injection vulnerabilities.
Audit Metadata