skills/celeroncoder/skills/slideshow/Gen Agent Trust Hub

slideshow

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to run npx hyperframes skills update slideshow to refresh its instructions and dependencies. This pattern involves downloading and executing code from the NPM registry at runtime.
  • [COMMAND_EXECUTION]: The skill makes extensive use of CLI tools for its workflow, including hyperframes present, hyperframes preview, hyperframes lint, and hyperframes check. These commands are used to serve, validate, and render the slideshow projects.
  • [EXTERNAL_DOWNLOADS]: The skill references the Three.js library from the jsdelivr.net CDN, a well-known service, to enable 3D visual effects within the slideshow compositions.
  • [PERSISTENCE]: The skill implements a persistence mechanism for speaker notes using the browser's localStorage. Notes are stored and retrieved using deterministic keys derived from the deck's URL and title.
  • [DYNAMIC_EXECUTION]: The references/standalone-harness.md file contains significant JavaScript logic intended to be injected into user projects. This includes a bootstrap script that uses parent.postMessage(..., "*") to communicate timeline metadata. The use of the * wildcard for the target origin is an insecure practice that can allow unintended origins to intercept the data.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes structured data from a JSON island inside HTML files, which includes user-controllable fields such as notes and label that are subsequently displayed to the user.
  • Ingestion points: Data is read from <script type="application/hyperframes-slideshow+json"> blocks within composition files like index.html.
  • Boundary markers: The data is encapsulated within a specific JSON schema and script type identifier.
  • Capability inventory: The skill has the ability to write files, execute subprocesses via the hyperframes CLI, and perform network operations through the agent's environment.
  • Sanitization: The instructions emphasize SVG sanitization and font token resolution but do not detail specific sanitization for natural language fields in the JSON manifest.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — slideshow