algorithmic-art

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the p5.js library from a trusted, well-known content delivery network (https://cdnjs.cloudflare.com/ajax/libs/p5.js/1.7.0/p5.min.js). This is a standard and safe dependency for the skill's intended purpose.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided 'conceptual seeds' to drive the creation of artistic manifestos and executable JavaScript code, which creates a theoretical attack surface for indirect prompt injection.\n
  • Ingestion points: User-provided inputs derived from the 'conceptual seed' in SKILL.md are interpolated into generated files.\n
  • Boundary markers: Absent. The skill does not specify the use of delimiters or 'ignore embedded instructions' markers to separate user data from instructions.\n
  • Capability inventory: The skill uses tools to read internal template files (templates/viewer.html) and write new code files (.md, .html, .js) to the agent's workspace.\n
  • Sanitization: Absent. There are no instructions for validating or escaping the user-supplied art concepts before they are used in code generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:56 AM
Security Audit — agent-trust-hub — algorithmic-art