slides-grab
Warn
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
scripts/install.shscript and installation instructions perform automated downloads of external software, including theslides-grabpackage from npm and Chromium via Playwright. - [REMOTE_CODE_EXECUTION]: The skill executes code downloaded from external sources during the installation process and through runtime operations like
slides-grab edit, which launches a local server. - [COMMAND_EXECUTION]: The skill uses the
Bashtool to execute various CLI commands for slide generation, validation, and export, includingslides-grab,yt-dlp, andnpxcommands. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. Attackers could embed malicious instructions in the source topics, notes, or external assets (images/videos) that the agent processes and renders into slide content.
- Ingestion points: User-provided topic notes, external assets fetched via
WebFetch, and images generated via external providers. - Boundary markers: None detected in the instructions to prevent the agent from following instructions embedded in the slide HTML.
- Capability inventory: The skill has
Bashexecution,Read/Writefile access, andWebFetchnetwork capabilities. - Sanitization: No evidence of sanitization for the HTML/CSS content generated from untrusted inputs.
- [CREDENTIALS_UNSAFE]: The skill interacts with sensitive authentication files, specifically
~/.codex/auth.json, and requires users to provideOPENAI_API_KEYorGOOGLE_API_KEYfor specific image generation providers. - [REMOTE_CODE_EXECUTION]: The default image generation provider,
god-tibo-imagen, utilizes an 'unsupported private Codex backend', which represents an opaque and potentially insecure execution environment.
Audit Metadata