slides-grab-design
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external outline files and template packs which represent a potential injection surface. Evidence: Found in SKILL.md steps 1 and 2. The skill incorporates boundary markers by employing the 'BEGIN UNTRUSTED TEMPLATE PACK DATA' tag. The capability inventory includes file creation, asset generation, and CLI tool execution. Sanitization is present as the instructions explicitly direct the agent to treat template pack data as design data only and to never execute imperative text from imported sources.
- [COMMAND_EXECUTION]: The skill utilizes a custom CLI tool 'slides-grab' and the 'yt-dlp' utility for slide generation, validation, and asset fetching. These operations are within the scope of the skill's primary purpose.
- [EXTERNAL_DOWNLOADS]: The skill fetches resources from well-known services and CDNs, including Lucide icons, Chart.js from jsDelivr, Mermaid from jsDelivr, and the Pretendard font from GitHub. These are categorized as safe, trusted sources.
- [DATA_EXPOSURE]: The skill references the path '~/.codex/auth.json' for authentication with the image generation backend. This is handled via standard developer CLI login procedures and is specific to the tool's required functionality.
Audit Metadata