tutorial-generator

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted input from screenshots and user-provided context via an LLM, which represents a surface for indirect prompt injection.
  • Ingestion points: The screenshot file content and the --context parameter in scripts/generate_tutorial.py are interpolated into the prompt for the Gemini Vision model.
  • Boundary markers: The prompt in scripts/generate_tutorial.py does not use explicit delimiters or instructions to separate instructions from external analyzed content.
  • Capability inventory: The script has the capability to write to the local filesystem using Path.write_text in scripts/generate_tutorial.py to save generated tutorials.
  • Sanitization: The script does not perform HTML escaping or sanitization of the strings returned by the LLM before embedding them into the final HTML template, which could lead to Cross-Site Scripting (XSS) if the LLM is manipulated into producing malicious script tags.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 08:27 PM
Security Audit — agent-trust-hub — tutorial-generator