deck-guizang-editorial
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions are focused on layout and design constraints. No attempts to override safety guidelines, bypass instructions, or extract system prompts were observed.- [REMOTE_CODE_EXECUTION]: The example HTML includes links to
cdn.tailwindcss.comandfonts.googleapis.com. These are well-known and trusted external services used for styling and typography, and do not constitute unsafe remote code execution.- [DATA_EXFILTRATION]: There are no patterns suggesting unauthorized data access or transmission to external servers. The skill does not reference sensitive local files, credentials, or environment variables.- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied content to generate a slide deck. - Ingestion points: User content is interpolated into HTML templates as described in SKILL.md.
- Boundary markers: None explicitly defined in the instructions.
- Capability inventory: The skill only generates static HTML and does not have capabilities for file modification, network requests, or command execution.
- Sanitization: No specific sanitization instructions are provided, but the lack of dangerous capabilities makes this surface safe.- [SAFE]: The skill is a stylistic template for presentation generation and does not contain any code or configuration that poses a security risk.
Audit Metadata