thirds-carousels

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external design data, including template sources, schemas, and JSON manifests from the thirds.ai platform.
  • Ingestion points: Design page IDs, source code, and manifest.json files identified in SKILL.md.
  • Capability inventory: The skill utilizes the create_carousel and get_status tools to process this data and perform file downloads.
  • Boundary markers: None defined in the instructions to separate design content from agent instructions.
  • Sanitization: No explicit sanitization of the design metadata is described before processing.
  • [EXTERNAL_DOWNLOADS]: The skill fetches design archives and references documentation from the author's official domain (thirds.ai) and public GitHub repository (github.com/thirdsai). These are verified vendor resources belonging to the skill creator.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 01:23 PM
Security Audit — agent-trust-hub — thirds-carousels