sn-ppt-creative

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data including user queries, document digests, and reference images which are then used to generate prompts for downstream AI models.
  • Ingestion points: info_pack.json (containing user_query and document_digest) and reference image paths are read in Stage 2, 3, and 4 in SKILL.md.
  • Boundary markers: The prompt templates in prompts/outline.md and prompts/page_prompt.md lack explicit boundary markers or instructions to ignore embedded commands in the user data.
  • Capability inventory: The skill can write files to the local deck directory and execute subprocesses (e.g., build_pptx.py, sn_agent_runner.py).
  • Sanitization: The skill includes a dedicated script scripts/sanitize_prompt.py and hard constraints in prompts/page_prompt.md specifically designed to strip technical metadata like hex codes, CSS units, and design labels to prevent them from being rendered in generated images.
  • [COMMAND_EXECUTION]: The skill instructions in SKILL.md utilize shell command substitution and execution of local Python scripts to handle file processing and tool invocation.
  • Evidence: Stage 4.2 in SKILL.md uses $(cat ...) to interpolate the content of prompt files into the command line for the image generation tool.
  • [DYNAMIC_EXECUTION]: The skill uses python -c snippets to dynamically import shared libraries and execute logic involving interpolated environment variables and paths.
  • Evidence: Stage 2, 3, and 4.1 in SKILL.md use python3 -c to invoke the shared model_client for LLM and VLM operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:38 AM
Security Audit — agent-trust-hub — sn-ppt-creative