slide-storyline-designer
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data (raw slide material, scattered notes, or old decks) to generate logical skeletons for presentations. This represents a potential surface for indirect prompt injection.\n
- Ingestion points: Raw material and messages provided by the user in Step 1 (SKILL.md).\n
- Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions within the user-provided material.\n
- Capability inventory: The skill possesses the capability to read and write files within the project subfolder and access external documents via Google Drive (references/brand-source.md).\n
- Sanitization: The process description does not include specific sanitization or validation of the input content.\n- [REMOTE_CODE_EXECUTION]: Documentation references an installation command using
npxthat targets the author's GitHub repository (https://github.com/peter-tu-zynkr/zynkr-skill-builder) to install the skill.\n- [COMMAND_EXECUTION]: The brand source reference mentions a synchronization script (scripts/sync-brand-guide.py) used to keep brand guidelines updated from a Git repository.
Audit Metadata