skills/glaucia86/skills/revealjs/Gen Agent Trust Hub

revealjs

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to generate HTML artifacts that load the reveal.js core library and several plugins (highlight, markdown, notes, math, search, zoom) from the jsDelivr CDN (cdn.jsdelivr.net), which is a well-known and trusted service for front-end assets.
  • [EXTERNAL_DOWNLOADS]: The generated presentations download CSS themes and JavaScript resources from the official reveal.js project via the jsDelivr CDN.
  • [SAFE]: No malicious obfuscation, credential theft, or unauthorized persistence mechanisms were detected. The skill follows best practices for the reveal.js library.
  • [SAFE]: Indirect Prompt Injection analysis: (1) Ingestion points: User-provided text, outlines, and notes used to generate presentation slides. (2) Boundary markers: None; content is interpolated into HTML templates. (3) Capability inventory: The generated HTML files execute JavaScript and can load external resources via iframes or data attributes. (4) Sanitization: Not explicitly handled; instructions even mention features to disable escaping for code blocks. Given the context of a presentation generator, this is considered a standard functional surface rather than a vulnerability.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 02:23 PM
Security Audit — agent-trust-hub — revealjs