huashu-slides

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions (SKILL.md) guide the agent to construct and execute shell commands using the uv run and npx playwright tools. Specifically, in Step 3-A and Step 3-B, user-provided descriptions and slide content are interpolated directly into command-line arguments for image generation scripts. This pattern creates a high risk of command injection if the input contains shell metacharacters (e.g., backticks, semicolons, or pipe symbols).
  • [DYNAMIC_EXECUTION]: The PPTX assembly logic in Path A utilizes a Node.js require call that dynamically loads a script from a path computed using process.env.HOME. Loading executable code from paths that can be influenced by local environment variables or other skill installations is a potential vector for local privilege escalation or execution of malicious code if the dependency skill is compromised.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge, taking raw material from users to generate complex prompts for downstream AI image generation models (Gemini via nano-banana-pro). This surface is vulnerable to indirect prompt injection where a user provides content designed to manipulate the behavior of the image generation script or the shell environment in which it runs.
  • [CREDENTIALS_SAFE]: The skill correctly instructs the user to manage their GEMINI_API_KEY within a local .env file and loads it using grep. While this involves accessing a sensitive file (~/.claude/.env), it follows standard local development practices for secret management and does not exfiltrate the key to external domains.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:55 AM
Security Audit — agent-trust-hub — huashu-slides