theme-factory
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected in the skill instructions or theme files. The skill operates locally on visual metadata (colors and fonts) and does not require external network access or administrative privileges.- [PROMPT_INJECTION]: The instructions are focused on theme application and do not contain attempts to bypass safety filters or override system-level behavioral constraints.- [DATA_EXFILTRATION]: There are no commands that access sensitive user data, environment variables, or secret keys, and no network tools are used to send data externally.- [REMOTE_CODE_EXECUTION]: The skill does not reference external dependencies or execute scripts. It relies on internal markdown files for theme definitions.- [INDIRECT_PROMPT_INJECTION]: The skill allows for custom theme generation based on user input. However, the scope is limited to visual attributes (hex codes and font names), and a verification step is included where the agent must show the generated theme for review before applying it.
Audit Metadata