feature-presentation
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from session-generated artifacts. Ingestion points: Reads files from the team-artifacts/ and docs/specs/ directories. Boundary markers: Content is isolated within srcdoc attributes. Capability inventory: Uses the spawn_agent tool for sub-tasks and performs local file read/write operations to generate the deck. Sanitization: Employs a specific, non-idempotent HTML entity escaping protocol (escaping &, ", <, and > in order) to ensure embedded mockup code cannot break out of the iframe or execute in the parent context.
- [DYNAMIC_EXECUTION]: The skill generates a self-contained HTML file that includes an inline vanilla JavaScript engine (~60 lines). This script is used for slide navigation, keyboard events, and theme toggling. The code is transparently documented and avoids external library dependencies.
- [UNVERIFIABLE_DEPENDENCIES]: The generated output references Google Fonts (fonts.googleapis.com) to maintain project-faithful styling. This is a trusted, well-known service for static assets and does not involve executable code downloads.
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the spawn_agent tool to orchestrate multi-step workflows (like workflow-spec-to-pbi) as sub-agents. This allows the skill to gap-fill missing artifacts within a controlled environment.
Audit Metadata