html-ppt-zhangzara-stencil-tablet
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill workflow requires the agent to populate an HTML template with user-provided text content such as headlines, body copy, and section labels (SKILL.md). The absence of explicit sanitization instructions or boundary markers for this interpolation process creates a standard surface for indirect prompt injection.
- Ingestion points: User-supplied text and numeric data used to replace placeholders in example.html.
- Boundary markers: Absent.
- Capability inventory: The agent generates a functional HTML deck artifact.
- Sanitization: No instructions provided for filtering or escaping user-provided input.
- [EXTERNAL_DOWNLOADS]: The template references font resources from Google Fonts, a well-known and trusted service.
- Evidence: URL references to fonts.googleapis.com and fonts.gstatic.com in example.html.
Audit Metadata