pattern-generator
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMMETADATA_POISONINGPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [METADATA_POISONING]: The skill's frontmatter defines the license as 'Proprietary', but the included LICENSE.txt contains the full text of the Apache License 2.0. This contradiction is deceptive and provides conflicting information to users regarding their rights to use and modify the skill.\n- [PROMPT_INJECTION]: The instructions in SKILL.md explicitly direct the agent that user input 'should not constrain creative freedom,' which serves as a directive to prioritize the skill's generated 'philosophy' over specific user requirements. Additionally, the skill employs repetitive, high-pressure language to bias the agent's output persona toward an 'expert' tone.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied conceptual seeds to generate executable p5.js art, which introduces a potential vulnerability surface.\n
- Ingestion points: User-provided inputs are incorporated into the generation process in SKILL.md.\n
- Boundary markers: The instructions lack clear delimiters or safety markers to isolate untrusted user data from the generated code.\n
- Capability inventory: The skill produces interactive HTML and JavaScript artifacts that execute in the user's environment.\n
- Sanitization: No escaping, validation, or filtering is applied to the user-supplied seed before it is used in the p5.js implementation.\n- [EXTERNAL_DOWNLOADS]: The skill fetches the p5.js library from the well-known Cloudflare CDN for use in the generated artifacts.
Audit Metadata