material-theming
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill involves analyzing and refactoring user-provided Flutter widget and theme code, which creates a surface for indirect prompt injection.
- Ingestion points: The agent reads source files, including widget styling and
ThemeDataconfigurations, from the user's workspace usingRead,Grep, andGlobtools. - Boundary markers: The instructions do not define boundary markers or clear separators to distinguish between project code and instructions for the agent.
- Capability inventory: The skill is restricted to file inspection tools (
Read,Grep,Glob); no file-writing, network communication, or code execution tools are requested in the configuration. - Sanitization: There is no explicit sanitization or validation of the code snippets ingested by the agent before processing.
Audit Metadata