presentation-architect
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that relies on ingesting potentially untrusted data, creating an indirect prompt injection surface.\n
- Ingestion points: The instructions explicitly require the agent to read and reference external data from 'research-notes.md' and potentially user-provided URLs to populate the requirements, storyline, and slide outlines (Step 1, Step 4, and Quality Gates).\n
- Boundary markers: The skill lacks instructions for the agent to use delimiters or specific boundary markers when processing external data, nor does it include warnings to ignore instructions embedded within the ingested content.\n
- Capability inventory: The skill is capable of writing and modifying project markdown files (requirements.md, storyline.md, slide-outline.md). It does not have capabilities for network requests, shell command execution, or dynamic code evaluation.\n
- Sanitization: There are no provisions for sanitizing, validating, or filtering the content retrieved from external sources before it is interpolated into the design documents.
Audit Metadata