gslides-creator
Warn
Audited by Snyk on May 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly reads template content from arbitrary Google Slides (DriveApp.getFileById / SlidesApp.openById via gslides-parser and convertSlides.js listPlaceholders) and includes those untrusted placeholder texts in the Gemini prompt to generate replacements (scripts/gslides_creator.py -> _generate_replacements), and it can also fetch external images from arbitrary image_url in gas/deckSlides.js, so third-party content can influence model outputs and subsequent slide creation.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata