slide-storyline-designer

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data (raw slide material, scattered notes, or old decks) to generate logical skeletons for presentations. This represents a potential surface for indirect prompt injection.\n
  • Ingestion points: Raw material and messages provided by the user in Step 1 (SKILL.md).\n
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions within the user-provided material.\n
  • Capability inventory: The skill possesses the capability to read and write files within the project subfolder and access external documents via Google Drive (references/brand-source.md).\n
  • Sanitization: The process description does not include specific sanitization or validation of the input content.\n- [REMOTE_CODE_EXECUTION]: Documentation references an installation command using npx that targets the author's GitHub repository (https://github.com/peter-tu-zynkr/zynkr-skill-builder) to install the skill.\n- [COMMAND_EXECUTION]: The brand source reference mentions a synchronization script (scripts/sync-brand-guide.py) used to keep brand guidelines updated from a Git repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 07:31 PM
Security Audit — agent-trust-hub — slide-storyline-designer