html-ppt
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEOBFUSCATIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [OBFUSCATION]: The template
templates/full-decks/testing-safety-alert/index.htmluses HTML entities (e.g.,mfor 'm') to encode potentially dangerous shell commands likerm -rf /and SQL commands likedrop table. This is used defensively to display these commands as text examples in a security-themed presentation slide without triggering simple keyword filters or accidental execution. - [DYNAMIC_EXECUTION]: The
assets/animations/fx-runtime.jsscript implements a dynamic plugin loader that identifies elements withdata-fxattributes and injects corresponding script tags from theassets/animations/fx/directory. While this involves runtime code loading, it is restricted to a predefined list of local animation modules. - [COMMAND_EXECUTION]: The
scripts/render.shscript facilitates the conversion of HTML slides to PNG images by executing Google Chrome in headless mode. It uses the--no-sandboxflag, which is a common requirement for headless environments but expands the browser's attack surface if rendering untrusted remote content; however, the script is designed to operate on localfile://URLs generated by the skill. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to interpolate user-provided data into HTML templates. This creates a surface where malicious instructions could be embedded in the processed data. The skill lacks explicit sanitization of this content, relying on the agent's internal guardrails and the user's review of the generated HTML files.
- [EXTERNAL_DOWNLOADS]: Several templates (e.g.,
chart-bar.html,code.html) reference external JavaScript libraries includingChart.jsandhighlight.jsfrom the establishedcdn.jsdelivr.netCDN. These are well-known services used for their intended purposes of data visualization and code highlighting.
Audit Metadata