theme-factory
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of static markdown theme definitions and standard instructional text for an AI agent. No malicious patterns such as command execution, remote downloads, persistence mechanisms, or unauthorized file access were detected across the analyzed files. The provided hex codes and font references (DejaVu, FreeSans) are standard and benign.
- [PROMPT_INJECTION]: The skill includes an indirect prompt injection surface in the 'Create your Own Theme' feature, which processes user-provided descriptions to generate new themes. 1. Ingestion points: User-provided text descriptions for custom theme generation in SKILL.md. 2. Boundary markers: Absent; the agent is not instructed to isolate or ignore potential instructions within the user's description. 3. Capability inventory: The skill's primary capabilities are reading theme files and applying visual styling to user artifacts (e.g., slide decks). 4. Sanitization: No specific validation or sanitization of user-provided theme descriptions is defined. This surface is considered low risk given the skill's limited styling scope.
Audit Metadata