skills/marswaveai/skills/slides/Gen Agent Trust Hub

slides

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands using a specialized CLI tool (listenhub). These commands are used for authenticating the user, managing configuration files (jq), and triggering the slide generation process. All commands follow a strict interactive flow requiring explicit user confirmation before execution.
  • [EXTERNAL_DOWNLOADS]: When optional narration is enabled, the skill uses curl to download generated audio files from listenhub.ai. This is a core functional requirement of the tool and targets the vendor's own verified infrastructure.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads and writes configuration data to a hidden directory (.listenhub/) and saves generated artifacts to the current working directory. It explicitly forbids saving to sensitive locations like ~/Downloads/. No unauthorized data transmission to third-party domains was detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data such as user-provided topics and content from external URLs. However, it implements a hard-gated interaction flow using the AskUserQuestion tool to confirm all parameters before processing, mitigating the risk of instructions embedded in the input data being automatically obeyed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:40 AM