board-deck-generator
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill contains an indirect prompt injection attack surface where untrusted data could influence agent behavior. \n
- Ingestion points: The
SKILL.mdworkflow explicitly directs the agent to read user-provided 'prior board deck' files to maintain continuity in tracking metrics and narratives. \n - Boundary markers: The instructions lack delimiters or explicit directives to isolate content from these external files or to ignore potential instructions embedded within them. \n
- Capability inventory: The skill utilizes tools with high capability, specifically
Bash,Write, andRead(as defined in the frontmatter), which could be abused if malicious instructions are present in the ingested files. \n - Sanitization: There is no mention of sanitizing or validating the contents of the prior decks before they are processed by the agent.
Audit Metadata