theme-factory

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill primarily consists of design metadata (hex codes and font names) and instructional markdown. It does not include any executable scripts, binary files, or commands that interact with the network or sensitive system paths.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to generate custom themes based on user-provided descriptions, which represents a potential surface for indirect prompt injection.
  • Ingestion points: User-provided descriptions used to choose colors and fonts for custom themes.
  • Boundary markers: None identified in the skill body.
  • Capability inventory: Reading theme files from the local directory and modifying artifact styling.
  • Sanitization: No specific sanitization logic is present; the skill relies on the agent's core safety guardrails during content generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — theme-factory