ui-theming

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • Indirect Prompt Injection (SAFE): The skill ingests user-provided reference images and brand descriptions. The risk is considered negligible as the agent's capabilities are focused on generating static UI code and visual verification using standard testing tools.
  • Ingestion points: Reference images and style descriptions provided by the user.
  • Boundary markers: None explicitly defined.
  • Capability inventory: launch_app, take_screenshot, and inspect_view_hierarchy via Dart and Maestro MCPs.
  • Sanitization: None. \n- External Downloads (SAFE): The skill references the google_fonts package, which is a standard and trustworthy dependency in the Flutter ecosystem. \n- Command Execution (SAFE): The skill utilizes legitimate development MCPs (Dart and Maestro) for application lifecycle management and automated UI testing, which is appropriate for its stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 09:22 PM