feature-presentation

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from session-generated artifacts. Ingestion points: Reads files from the team-artifacts/ and docs/specs/ directories. Boundary markers: Content is isolated within srcdoc attributes. Capability inventory: Uses the spawn_agent tool for sub-tasks and performs local file read/write operations to generate the deck. Sanitization: Employs a specific, non-idempotent HTML entity escaping protocol (escaping &, ", <, and > in order) to ensure embedded mockup code cannot break out of the iframe or execute in the parent context.
  • [DYNAMIC_EXECUTION]: The skill generates a self-contained HTML file that includes an inline vanilla JavaScript engine (~60 lines). This script is used for slide navigation, keyboard events, and theme toggling. The code is transparently documented and avoids external library dependencies.
  • [UNVERIFIABLE_DEPENDENCIES]: The generated output references Google Fonts (fonts.googleapis.com) to maintain project-faithful styling. This is a trusted, well-known service for static assets and does not involve executable code downloads.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the spawn_agent tool to orchestrate multi-step workflows (like workflow-spec-to-pbi) as sub-agents. This allows the skill to gap-fill missing artifacts within a controlled environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — feature-presentation