material-theming

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill involves analyzing and refactoring user-provided Flutter widget and theme code, which creates a surface for indirect prompt injection.
  • Ingestion points: The agent reads source files, including widget styling and ThemeData configurations, from the user's workspace using Read, Grep, and Glob tools.
  • Boundary markers: The instructions do not define boundary markers or clear separators to distinguish between project code and instructions for the agent.
  • Capability inventory: The skill is restricted to file inspection tools (Read, Grep, Glob); no file-writing, network communication, or code execution tools are requested in the configuration.
  • Sanitization: There is no explicit sanitization or validation of the code snippets ingested by the agent before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 01:53 PM
Security Audit — agent-trust-hub — material-theming