scientific-slides

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Several scripts utilize subprocess.run to orchestrate internal workflows and interface with document processing tools like pdflatex.
  • Evidence: Found in scripts/generate_schematic.py, scripts/validate_presentation.py, and scripts/generate_slide_image.py.
  • Analysis: The calls are implemented securely using argument lists rather than shell strings (shell=False). The pdflatex invocation specifically uses the -no-shell-escape flag to prevent arbitrary command execution during LaTeX compilation.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with an external AI provider to generate images and review slide quality.
  • Evidence: Scripts scripts/generate_schematic_ai.py and scripts/generate_slide_image_ai.py perform network requests to https://openrouter.ai/api/v1/chat/completions.
  • Analysis: These connections are directed to OpenRouter, a well-known service for accessing large language models, and are essential for the skill's primary purpose. Credential management for this service follows best practices by using environment variables or .env files rather than hardcoded secrets.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text to describe slides and schematics, which is then interpolated into AI prompts without extensive sanitization.
  • Ingestion points: The prompt command-line argument in scripts/generate_slide_image.py and scripts/generate_schematic.py accepts arbitrary strings from the user.
  • Boundary markers: The skill does not employ specific delimiters or instruction-guarding techniques to isolate this untrusted input from the rest of the generated prompt.
  • Capability inventory: The skill has the capability to write local files and make outbound network requests to the OpenRouter API.
  • Sanitization: There is no evidence of filtering or escaping user input before it is used to generate prompts for the AI image generation and review models.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — scientific-slides