theme-factory

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill functions as a static library of professional design themes, providing color hex codes and font pairings for use in presentations. The analysis detected no malicious logic or dangerous commands.- [NO_CODE]: The skill package is composed strictly of markdown documentation and configuration files. It lacks any executable scripts (e.g., Python or JavaScript) or binary components.- [DATA_EXFILTRATION]: No network operations or commands capable of transmitting data externally (such as curl or wget) were found in the skill instructions.- [REMOTE_CODE_EXECUTION]: The skill does not include any mechanisms for downloading, installing, or executing code from remote sources.- [PROMPT_INJECTION]: There are no detected instructions designed to bypass agent safety guidelines or override system behavior.- [SAFE]: The skill processes data from the themes directory and user input for custom themes, which constitutes an ingestion surface for indirect prompt injection. Given the limited application to styling, this is evaluated as safe. * Ingestion points: Markdown files in the themes/ directory and user-provided descriptions for custom themes. * Boundary markers: Not specified in the instructions. * Capability inventory: Reading local files from the themes/ directory. * Sanitization: Not explicitly implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 06:11 PM