thirds-create-template

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted user data, such as HTML strings and natural language prompts, to generate design templates. While this creates an attack surface for indirect prompt injection, it is the primary intended function of the skill. The instructions mitigate risk by requiring a human-in-the-loop review process where the user must verify the draft in the thirds.ai editor before calling the publish tool.
  • Ingestion points: User-supplied HTML, prompts, and images processed via the create_template tool in SKILL.md.
  • Boundary markers: The skill instructs the agent to ask the user to review results in an external editor before publishing.
  • Capability inventory: Calls to MCP tools for template creation, polling status, and publishing.
  • Sanitization: Instructions do not explicitly mention input sanitization, but rely on the platform's template engine and user review.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and design resources from the vendor's official website (thirds.ai) and a related skill in their official GitHub repository. These references are for configuration and guidance purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 02:08 PM
Security Audit — agent-trust-hub — thirds-create-template