quarto-deck

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied markdown content which is later evaluated by a rhetoric reviewer sub-agent. While this creates a potential surface for indirect injection, the risk is inherent to document processing tasks and is mitigated by the specific scope of the rhetoric review.\n
  • Ingestion points: Context gathering (Phase 1) and deck building (Phase 3) where user files and project content are read.\n
  • Boundary markers: Not explicitly defined in the sub-agent prompt, though the prompt clearly scopes the task to rhetoric evaluation.\n
  • Capability inventory: The sub-agent has Read access to the markdown files and project documentation.\n
  • Sanitization: No explicit content sanitization is described, as the content is passed directly to the reviewer sub-agent.\n- [DYNAMIC_EXECUTION]: The skill instructs the agent to generate and execute R or Python scripts to produce figures for the presentation. These operations are performed using standard tools like 'uv run python' and are a core part of the skill's intended functionality for creating data-driven slides.\n- [UNVERIFIABLE_DEPENDENCIES]: The documentation mentions installing 'reveal-md' via npm. This is a well-known open-source utility for rendering presentations and its usage here is considered safe as it is central to the skill's purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 06:17 AM
Security Audit — agent-trust-hub — quarto-deck