theme-factory

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The 'Create your Own Theme' feature in SKILL.md allows for custom theme generation based on user-provided descriptions, which presents an attack surface for indirect prompt injection.
  • Ingestion points: User-provided inputs and basic descriptions for generating custom themes as specified in SKILL.md.
  • Boundary markers: No explicit delimiters or boundary markers are used to isolate the generated theme values from instructions.
  • Capability inventory: The agent has the capability to 'Apply the selected theme' to artifacts, which involves modifying file content in slide decks, documents, and HTML pages.
  • Sanitization: No sanitization, escaping, or validation of user-provided descriptions or the generated theme values is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:28 PM
Security Audit — agent-trust-hub — theme-factory