deck-swiss-international

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection due to the handling of user-provided data. * Ingestion points: User-provided text, product data, and methodology descriptions are ingested to populate the 22 slide layouts defined in SKILL.md. * Boundary markers: Absent. There are no instructions to use delimiters or to ignore instructions found within the user content. * Capability inventory: The skill generates full HTML and CSS output (as seen in example.html). * Sanitization: Absent. The instructions do not mandate the sanitization or escaping of external content before its interpolation into the HTML output.
  • [EXTERNAL_DOWNLOADS]: The skill references styling and typography assets from well-known external services. * Loads the Tailwind CSS library via a script tag from cdn.tailwindcss.com in the example.html file. * Fetches font families from Google Fonts (fonts.googleapis.com) to maintain the design system's aesthetic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:57 PM
Security Audit — agent-trust-hub — deck-swiss-international