sn-ppt-story

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from sources like 'raw_documents.json' and 'research_report' without explicit instruction boundary markers. This data is synthesized into an 'outline.md' file that governs downstream presentation generation, creating a surface for indirect prompt injection attacks.
  • Ingestion points: '<DECK_DIR>/info_pack.raw_documents', '<DECK_DIR>/info_pack.research_report', and other user-specified source files.
  • Boundary markers: The instructions do not specify delimiters or 'ignore instructions' warnings to prevent the agent from obeying commands embedded in the processed documents.
  • Capability inventory: File system write access to the project directory to update 'outline.md' and 'task_pack.json'.
  • Sanitization: No sanitization, escaping, or schema validation is mentioned for the ingested document content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 AM
Security Audit — agent-trust-hub — sn-ppt-story