slack-gif-creator
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided images, which serves as a potential surface for indirect instructions if the agent is directed to interpret image content.
- Ingestion points: User-uploaded files are processed via
Image.open()in the core workflow described inSKILL.md. - Boundary markers: None; the skill does not provide explicit delimiters or warnings for the agent to ignore instructions potentially embedded within image metadata or visual data.
- Capability inventory: The skill includes file system read access for validation in
core/validators.pyand file system write access for saving animations incore/gif_builder.py. - Sanitization: The skill validates technical constraints such as dimensions and frames in
core/validators.py, but it does not perform sanitization of the internal image content or metadata.
Audit Metadata