tutorial-generator
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted input from screenshots and user-provided context via an LLM, which represents a surface for indirect prompt injection.
- Ingestion points: The screenshot file content and the
--contextparameter inscripts/generate_tutorial.pyare interpolated into the prompt for the Gemini Vision model. - Boundary markers: The prompt in
scripts/generate_tutorial.pydoes not use explicit delimiters or instructions to separate instructions from external analyzed content. - Capability inventory: The script has the capability to write to the local filesystem using
Path.write_textinscripts/generate_tutorial.pyto save generated tutorials. - Sanitization: The script does not perform HTML escaping or sanitization of the strings returned by the LLM before embedding them into the final HTML template, which could lead to Cross-Site Scripting (XSS) if the LLM is manipulated into producing malicious script tags.
Audit Metadata