sn-ppt-dazzle

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from outline.md and task_pack.json. This data is interpolated into generated HTML and JavaScript files without explicit sanitization or boundary markers. The resulting files are سپس executed in a headless browser environment (Playwright) for rendering.\n
  • Ingestion points: SKILL.md reads content from outline.md and metadata from task_pack.json.\n
  • Boundary markers: Absent. The instructions do not provide delimiters or instructions to ignore embedded commands in the source data.\n
  • Capability inventory: The skill uses playwright to execute generated web code and runs a local Python script for automation.\n
  • Sanitization: Absent. There is no evidence of escaping or validating the content from the outline before it is included in the executable HTML/JS.\n- [DYNAMIC_EXECUTION]: The skill dynamically generates HTML and JavaScript at runtime. It then uses the playwright library within the render_deck.py script to execute this generated code. This verification step involves running code that incorporates external data within a browser sandbox.\n- [EXTERNAL_DOWNLOADS]: The generated presentation code includes references to standard libraries (Three.js, GSAP, ECharts, D3) and fonts (Google Fonts) hosted on trusted Content Delivery Networks, including cdnjs.cloudflare.com and fonts.googleapis.com. These are legitimate external resources from well-known services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 AM
Security Audit — agent-trust-hub — sn-ppt-dazzle