pitch-deck
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a local utility script,
scripts/verify.sh, designed to lint pitch deck outlines in markdown format. The script uses standard system tools likegrep,awk, andsedto perform read-only structural checks (e.g., verifying the presence of core slides and the inclusion of metrics). It does not perform any network operations, use privilege escalation, or access sensitive system directories. - [INDIRECT_PROMPT_INJECTION]: The skill acts on user-provided startup information (problem, solution, metrics) to generate deck structures. While this involves processing untrusted data, the skill is constrained to structural and narrative generation and does not have access to capabilities that could lead to data exfiltration or unauthorized system changes via prompt injection.
Audit Metadata