html-slide-plan
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data that could contain malicious instructions aimed at overriding agent behavior.
- Ingestion points: Untrusted data is ingested from DESIGN.md and unspecified user files or source material as indicated in the Inputs section.
- Boundary markers: The instructions lack delimiters or specific boundary markers to isolate untrusted input from the system instructions.
- Capability inventory: The skill is constrained to generating a slide_plan.json file and does not invoke risky capabilities such as shell commands, system modifications, or network access.
- Sanitization: No input validation or sanitization routines are defined to process the source materials before they are used in the planning phase.
Audit Metadata