huashu-slides
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions (SKILL.md) guide the agent to construct and execute shell commands using the
uv runandnpx playwrighttools. Specifically, in Step 3-A and Step 3-B, user-provided descriptions and slide content are interpolated directly into command-line arguments for image generation scripts. This pattern creates a high risk of command injection if the input contains shell metacharacters (e.g., backticks, semicolons, or pipe symbols). - [DYNAMIC_EXECUTION]: The PPTX assembly logic in Path A utilizes a Node.js
requirecall that dynamically loads a script from a path computed usingprocess.env.HOME. Loading executable code from paths that can be influenced by local environment variables or other skill installations is a potential vector for local privilege escalation or execution of malicious code if the dependency skill is compromised. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge, taking raw material from users to generate complex prompts for downstream AI image generation models (Gemini via nano-banana-pro). This surface is vulnerable to indirect prompt injection where a user provides content designed to manipulate the behavior of the image generation script or the shell environment in which it runs.
- [CREDENTIALS_SAFE]: The skill correctly instructs the user to manage their
GEMINI_API_KEYwithin a local.envfile and loads it usinggrep. While this involves accessing a sensitive file (~/.claude/.env), it follows standard local development practices for secret management and does not exfiltrate the key to external domains.
Audit Metadata