draft-slide-template-description

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external files (fields.yml, template.yml) and visual information from screenshots (screenshots/slide-01.png) to generate template descriptions. This represents an indirect prompt injection surface where malicious or misleading content within the source files could influence the agent's output.
  • Ingestion points: Files located at templates/<name>/fields.yml, templates/<name>/template.yml, and screenshots/slide-01.png (referenced in SKILL.md Steps 2 and 3).
  • Boundary markers: Absent. The skill does not define specific delimiters or instructions to the agent to ignore potentially malicious embedded content within the analyzed files.
  • Capability inventory: The skill performs file system read operations on template configuration and media files, and write operations to create or overwrite description.md (referenced in SKILL.md Step 4).
  • Sanitization: Absent. The skill does not specify validation or sanitization procedures for the data extracted from the source files before interpolation into the generated documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:07 AM
Security Audit — agent-trust-hub — draft-slide-template-description