slack-gif-creator
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-supplied images as frames or inspiration for GIF creation. This creates a surface for indirect prompt injection where malicious instructions could be embedded in the metadata (e.g., EXIF data) or the content of the uploaded files.
- Ingestion points: The
SKILL.mdfile (under 'Working with User-Uploaded Images') instructs the agent to load and work with user-provided images using thePILlibrary. - Boundary markers: The instructions do not define specific delimiters or "ignore embedded instructions" warnings for the external image data being processed.
- Capability inventory: The skill possesses file writing capabilities through
core/gif_builder.py, which uses theimageiolibrary to save GIFs to the local file system. - Sanitization: There is no mention of stripping metadata, validating image content, or sanitizing inputs before processing them into frames.
- [METADATA_POISONING]: The
_meta.jsonfile contains tags that are inconsistent with the skill's actual implementation. Specifically, it includes "javascript" and "web" tags for a skill that is implemented entirely in Python and focused on image manipulation. While likely a result of template reuse, such inaccuracies can mislead users or automated systems about the skill's execution environment and requirements.
Audit Metadata