pitch-deck
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided business details to create a structured JSON file (
pitch_data.json). This untrusted data is later processed by a script to populate slides in a PowerPoint document. While the skill does not explicitly provide sanitization or boundary markers for this metadata, the ingestion is confined to document generation and does not pose a risk of modifying the agent's core instructions or bypassing safety filters. - [COMMAND_EXECUTION]: The workflow involves the execution of local shell commands, specifically
grepto retrieve information from a reference file andpython3to run the generation script (scripts/create_pitch_deck.py). These operations are consistent with the skill's stated purpose of content organization and file creation.
Audit Metadata