theme-factory
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external artifacts such as presentations, documents, and HTML pages by extracting their current content structure to apply themes. This introduces a surface for indirect prompt injection where malicious instructions hidden in the data being themed could attempt to influence the agent's behavior.
- Ingestion points: SKILL.md workflows involve selecting target artifacts and extracting their content structure.
- Boundary markers: No explicit boundary markers or instructions to ignore embedded content within processed artifacts are defined.
- Capability inventory: While no tools are explicitly listed in the frontmatter, the skill's description and workflows imply capabilities for reading, styling, and generating files across multiple formats.
- Sanitization: There is no evidence of sanitization or validation of the content extracted from target artifacts.
Audit Metadata