theme-factory

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external artifacts such as presentations, documents, and HTML pages by extracting their current content structure to apply themes. This introduces a surface for indirect prompt injection where malicious instructions hidden in the data being themed could attempt to influence the agent's behavior.
  • Ingestion points: SKILL.md workflows involve selecting target artifacts and extracting their content structure.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded content within processed artifacts are defined.
  • Capability inventory: While no tools are explicitly listed in the frontmatter, the skill's description and workflows imply capabilities for reading, styling, and generating files across multiple formats.
  • Sanitization: There is no evidence of sanitization or validation of the content extracted from target artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 08:06 AM
Security Audit — agent-trust-hub — theme-factory