pitch-gen
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its handling of user-supplied data in AI prompts.
- Ingestion points: The argument from the command line is passed directly to the generatePitch function in src/index.ts.
- Boundary markers: The prompt 'Create pitch deck content for: ${idea}' does not use any delimiters (such as triple quotes or XML tags) or instructions to ignore embedded commands.
- Capability inventory: The skill uses the fs module to write generated content to the filesystem (src/cli.ts).
- Sanitization: There is no validation or filtering of the input string to remove potential injection patterns before it is sent to the LLM.
Audit Metadata