draft-slide-template-description
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external files (
fields.yml,template.yml) and visual information from screenshots (screenshots/slide-01.png) to generate template descriptions. This represents an indirect prompt injection surface where malicious or misleading content within the source files could influence the agent's output. - Ingestion points: Files located at
templates/<name>/fields.yml,templates/<name>/template.yml, andscreenshots/slide-01.png(referenced in SKILL.md Steps 2 and 3). - Boundary markers: Absent. The skill does not define specific delimiters or instructions to the agent to ignore potentially malicious embedded content within the analyzed files.
- Capability inventory: The skill performs file system read operations on template configuration and media files, and write operations to create or overwrite
description.md(referenced in SKILL.md Step 4). - Sanitization: Absent. The skill does not specify validation or sanitization procedures for the data extracted from the source files before interpolation into the generated documentation.
Audit Metadata