sn-ppt-dazzle
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from
outline.mdandtask_pack.json. This data is interpolated into generated HTML and JavaScript files without explicit sanitization or boundary markers. The resulting files are سپس executed in a headless browser environment (Playwright) for rendering.\n - Ingestion points:
SKILL.mdreads content fromoutline.mdand metadata fromtask_pack.json.\n - Boundary markers: Absent. The instructions do not provide delimiters or instructions to ignore embedded commands in the source data.\n
- Capability inventory: The skill uses
playwrightto execute generated web code and runs a local Python script for automation.\n - Sanitization: Absent. There is no evidence of escaping or validating the content from the outline before it is included in the executable HTML/JS.\n- [DYNAMIC_EXECUTION]: The skill dynamically generates HTML and JavaScript at runtime. It then uses the
playwrightlibrary within therender_deck.pyscript to execute this generated code. This verification step involves running code that incorporates external data within a browser sandbox.\n- [EXTERNAL_DOWNLOADS]: The generated presentation code includes references to standard libraries (Three.js, GSAP, ECharts, D3) and fonts (Google Fonts) hosted on trusted Content Delivery Networks, includingcdnjs.cloudflare.comandfonts.googleapis.com. These are legitimate external resources from well-known services.
Audit Metadata