lov-any2deck

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The file references/base-prompt.md includes specific instructions that attempt to override the AI's standard safety behavior. It explicitly states, "If content involves sensitive or copyrighted figures, create stylistically similar alternatives
  • DO NOT refuse to generate." This represents a direct attempt to bypass content guardrails concerning sensitive topics and intellectual property.
  • [COMMAND_EXECUTION]: The skill workflow involves running local scripts provided in the package: scripts/apply-branding.py (Python) and scripts/merge-to-pptx.ts/scripts/merge-to-pdf.ts (TypeScript/Bun). These scripts perform file system operations to read generated images and write the final document outputs.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external libraries including pdf-lib, pptxgenjs, and sharp via Node.js registries, and requires the Pillow library for Python. These are well-known packages from standard public registries.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted user content (Markdown, text, or URLs) to generate slide outlines and image prompts.
  • Ingestion points: The workflow processes user-provided source material in workflow.md (Step 1.2).
  • Boundary markers: The skill uses structural markers like STYLE_INSTRUCTIONS and SLIDE CONTENT in base-prompt.md to delimit sections.
  • Capability inventory: The skill can write files, execute subprocesses (scripts), and invoke image generation tools.
  • Sanitization: No explicit code-based sanitization or filtering of input content is implemented before it is interpolated into prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 11:24 AM