ljg-present

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill workflow involves executing local helper scripts (Tools/EmbedAssets.ts and Tools/ValidateDeck.ts) using the bun runtime to finalize and verify the generated presentation files.
  • [DYNAMIC_EXECUTION]: The validation script Tools/ValidateDeck.ts utilizes the node:vm module to execute and test the chart rendering logic in an isolated context. This is a defensive measure used to verify the integrity and correctness of the generated slides' code without exposing the primary environment.
  • [EXTERNAL_DOWNLOADS]: The skill embeds local font files and images into the final HTML using Base64 encoding to support offline use. The embedding script includes explicit security checks to block remote URLs and validates image headers (magic bytes) for PNG, JPEG, and WEBP formats to prevent the accidental or malicious inclusion of sensitive non-image files.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided outlines or content from external URLs. It mitigates injection risks by using a function-based JSON replacer when injecting data into the HTML template and by employing textContent for all data rendering in the slide viewer, which prevents cross-site scripting (XSS) and unauthorized code execution from the source data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 08:25 PM
Security Audit — agent-trust-hub — ljg-present