marp-slide

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill is composed entirely of Markdown templates, CSS assets, and reference documentation. It does not contain any executable scripts, binaries, or automated shell commands that run on the host system.
  • [EXTERNAL_DOWNLOADS]: The skill's CSS files and templates reference Google Fonts (fonts.googleapis.com) to provide professional typography. These are links to a well-known and established service for web resources and do not represent a security risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a framework for the agent to process user-provided content into presentation slides. While it does not use explicit boundary markers to separate untrusted user data, the output is restricted to static Markdown files, which does not present an exploitable surface for the agent's logic.
  • [COMMAND_EXECUTION]: The documentation describes how users can manually use the marp-cli to export their slides, but the skill itself does not attempt to invoke these or any other shell commands automatically.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:12 PM
Security Audit — agent-trust-hub — marp-slide