ideation
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes bash commands to initialize complex session directory structures and manages its own dependencies by invoking
pip installfor libraries likeweasyprintandpython-pptxduring the session. - [EXTERNAL_DOWNLOADS]: The skill uses
WebFetchto download content from user-specified URLs to be used as primary source material for the brainstorming agents. - [REMOTE_CODE_EXECUTION]: Production agents (
ArchivistandPresentation Agent) generate Python scripts (build_capsule.py,build_presentation.py) based on the session's 'Vision Document.' Since this document is synthesized from potentially untrusted external inputs (files and URLs), it creates a risk where malicious patterns in the source data could be translated into executable code within the build scripts. - [PROMPT_INJECTION]: The skill exhibits vulnerability to indirect prompt injection due to its processing of external data.
- Ingestion points:
SKILL.md(Action 1: Capture Sources) and the PRD action ingest data from local files, external URLs, and user descriptions. - Boundary markers: The agent prompts do not utilize clear delimiters or instructions to ignore instructions embedded within the processed content.
- Capability inventory: The orchestrator and agents have the ability to execute bash commands, perform network fetches, and generate/execute Python code.
- Sanitization: There is no evidence of sanitization, filtering, or validation of the ingested content before it is processed by the generative agents or used in script construction.
Audit Metadata