html-slide
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a multi-stage workflow that ingests untrusted data to generate executable code, creating a surface for indirect prompt injection.\n- Ingestion points: The workflow processes a reference design, user-provided source files, and a deck prompt to drive the creation of artifacts.\n- Boundary markers: No explicit boundary markers or instructions to isolate or disregard instructions within the source material are defined.\n- Capability inventory: The sequence generates HTML, CSS, and JavaScript files in the workspace (slides-html/) and suggests verification in a browser.\n- Sanitization: No sanitization or validation routines for content extracted from the source documents are defined before the data is used in code generation.
Audit Metadata