skills/lovstudio/skills/lov-bp-deck/Gen Agent Trust Hub

lov-bp-deck

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-provided content (outline.md) and project assets to generate presentation files.\n
  • Ingestion points: Reads external investor outlines, brand logos, and product screenshots.\n
  • Boundary markers: The instructions do not specify the use of delimiters or specific warnings to ignore instructions embedded within the user-provided outline.\n
  • Capability inventory: The skill has the ability to write various files (PPTX, PDF, PNG) to the local filesystem and execute the lov-any2deck tool.\n
  • Sanitization: There are no documented steps for sanitizing or validating the input text before it is used for deck generation.\n- [EXTERNAL_DOWNLOADS]: The skill specifies a dependency on lov-any2deck. As this tool shares the vendor naming convention ('lov-*'), it is recognized as a legitimate component of the developer's ecosystem.\n- [COMMAND_EXECUTION]: The workflow involves invoking the lov-any2deck tool as a core step in the presentation rendering process.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 06:59 AM
Security Audit — agent-trust-hub — lov-bp-deck