presentations
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection by ingesting untrusted raw user inputs used to define brand voice.
- Ingestion points: Raw user inputs and voice samples are stored in 02-DOCS/raw/brand/ as described in SKILL.md and references/brand-grounding.md.
- Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat these inputs as data rather than instructions when reading the compiled brand study.
- Capability inventory: The skill can execute shell commands via scripts/verify.sh and run generated Python scripts.
- Sanitization: No sanitization or validation of the ingested user samples is performed.
- [COMMAND_EXECUTION]: The skill relies on executing shell commands and scripts to perform deck validation and generation.
- Evidence: The file scripts/verify.sh executes several tools including grep, find, npx, and pdffonts on project files.
- Evidence: SKILL.md and references/markdown-decks.md instruct the agent to use npx to run presentation tools like Marp and Slidev.
- [DYNAMIC_EXECUTION]: The skill uses a template-based script generation and execution pattern for PowerPoint deliverables.
- Evidence: references/pptx-python.md provides a Python skeleton that the agent is expected to populate with slide content and then execute using
python build_deck.py. - [EXTERNAL_DOWNLOADS]: The skill fetches and installs dependencies from official public registries (NPM and PyPI).
- Evidence: References to @marp-team/marp-cli, slidev, and python-pptx are found in SKILL.md and reference documents.
- Note: These tools are from well-known projects and organizations, making the downloads safe in the context of standard development workflows.
Audit Metadata