ideation

Pass

Audited by Gen Agent Trust Hub on Mar 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes bash commands to initialize complex session directory structures and manages its own dependencies by invoking pip install for libraries like weasyprint and python-pptx during the session.
  • [EXTERNAL_DOWNLOADS]: The skill uses WebFetch to download content from user-specified URLs to be used as primary source material for the brainstorming agents.
  • [REMOTE_CODE_EXECUTION]: Production agents (Archivist and Presentation Agent) generate Python scripts (build_capsule.py, build_presentation.py) based on the session's 'Vision Document.' Since this document is synthesized from potentially untrusted external inputs (files and URLs), it creates a risk where malicious patterns in the source data could be translated into executable code within the build scripts.
  • [PROMPT_INJECTION]: The skill exhibits vulnerability to indirect prompt injection due to its processing of external data.
  • Ingestion points: SKILL.md (Action 1: Capture Sources) and the PRD action ingest data from local files, external URLs, and user descriptions.
  • Boundary markers: The agent prompts do not utilize clear delimiters or instructions to ignore instructions embedded within the processed content.
  • Capability inventory: The orchestrator and agents have the ability to execute bash commands, perform network fetches, and generate/execute Python code.
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the ingested content before it is processed by the generative agents or used in script construction.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 10, 2026, 12:39 AM