slides-grab-plan

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The skill ingests data via slides-grab import-template --input <path> (local files or templates) and slides-grab import-design <https-url> (external URLs) as described in SKILL.md.
  • Boundary markers: The skill uses explicit workflow steps and a conversion guide (references/design-md-to-slides-conversion.md) to map web content to slides, which provides some structural boundaries.
  • Capability inventory: The agent has the capability to write files (slide-outline.md, DESIGN.slides.md) and execute shell commands via the slides-grab CLI.
  • Sanitization: The workflow includes multiple mandatory human-in-the-loop checkpoints where the user must explicitly approve the style, the design conversion summary, and the final outline.
  • [COMMAND_EXECUTION]: The skill frequently invokes an external CLI tool, slides-grab, to perform operations like importing templates, listing styles, and parsing design files. This assumes the presence and safety of this tool in the execution environment.
  • [EXTERNAL_DOWNLOADS]: The command slides-grab import-design <https-url> allows the skill to fetch content from arbitrary HTTPS URLs provided during the planning process.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 01:52 AM
Security Audit — agent-trust-hub — slides-grab-plan