lov-any2deck
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The file
references/base-prompt.mdincludes specific instructions that attempt to override the AI's standard safety behavior. It explicitly states, "If content involves sensitive or copyrighted figures, create stylistically similar alternatives - DO NOT refuse to generate." This represents a direct attempt to bypass content guardrails concerning sensitive topics and intellectual property.
- [COMMAND_EXECUTION]: The skill workflow involves running local scripts provided in the package:
scripts/apply-branding.py(Python) andscripts/merge-to-pptx.ts/scripts/merge-to-pdf.ts(TypeScript/Bun). These scripts perform file system operations to read generated images and write the final document outputs. - [EXTERNAL_DOWNLOADS]: The skill relies on external libraries including
pdf-lib,pptxgenjs, andsharpvia Node.js registries, and requires thePillowlibrary for Python. These are well-known packages from standard public registries. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted user content (Markdown, text, or URLs) to generate slide outlines and image prompts.
- Ingestion points: The workflow processes user-provided source material in
workflow.md(Step 1.2). - Boundary markers: The skill uses structural markers like
STYLE_INSTRUCTIONSandSLIDE CONTENTinbase-prompt.mdto delimit sections. - Capability inventory: The skill can write files, execute subprocesses (scripts), and invoke image generation tools.
- Sanitization: No explicit code-based sanitization or filtering of input content is implemented before it is interpolated into prompts.
Audit Metadata