deck-creator
Fail
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The publishing module in 'playground/src/lib/server/publish.ts' handles a 'paymentKey' for on-chain publishing. While the skill attempts to redact this from logs, managing such a high-sensitivity credential within the agent's context is inherently risky.
- [EXTERNAL_DOWNLOADS]: The 'scripts/playground_server.ts' file includes logic to automatically execute 'bun install' if the 'node_modules' directory is missing, which downloads and installs numerous third-party packages from the public NPM registry without user intervention.
- [REMOTE_CODE_EXECUTION]: The skill uses 'npx --yes react-onchain deploy' in 'playground/src/lib/server/publish.ts', which downloads and executes a third-party software package at runtime.
- [COMMAND_EXECUTION]: The skill frequently executes system-level commands through 'spawnSync' and 'Bun.spawn'. These include 'vercel' for cloud deployment, 'zip' for asset packaging, 'sips' and 'osascript' for macOS-specific tasks, and Chrome/Chromium binaries for capturing slide screenshots for PDF generation.
- [DATA_EXFILTRATION]: The deck directory switching functionality in 'playground/src/app/api/switch-deck/route.ts' allows the agent to navigate and potentially read files from any subdirectory within the user's home folder. This provides a path for an attacker to trick the agent into accessing sensitive files such as SSH keys or cloud credentials.
- [INDIRECT_PROMPT_INJECTION]: The skill is a sophisticated data processing pipeline that generates HTML and images from external files like 'DECK-PLAN.md' and user-supplied direction strings. * Ingestion points: Untrusted data enters the agent context through 'DECK-PLAN.md', 'THEME.md', and user-supplied direction text. * Boundary markers: System prompts in 'playground/src/app/api/generate-html-slide/route.ts' use explicit labels like 'REQUIRED VERBATIM ON-SLIDE COPY CONTRACT' to separate data from instructions. * Capability inventory: The skill possesses extensive capabilities including shell command execution ('bun', 'zip', 'sips', 'chrome', 'vercel', 'npx'), file system writes, and network operations via deployment tools. * Sanitization: The skill performs basic cleaning of filenames and text content, but the complexity of the data ingestion surface remains a vulnerability point.
Recommendations
- AI detected serious security threats
Audit Metadata