present
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user research, source material, and existing artifacts to build presentations, which creates a surface for indirect prompt injection.
- Ingestion points: Workflow steps in
SKILL.md(Step 1 and 2) instruct the agent to read and inspect user-supplied material and existing artifacts as the basis for the presentation. - Boundary markers: The instructions lack specific delimiters or directions to ignore potentially malicious instructions embedded within the source documents (e.g., hidden text attempting to override the agent's behavior).
- Capability inventory: The skill possesses capabilities to write files and utilize platform-specific authoring tools to generate HTML, PDF, and native slide decks.
- Sanitization: There are no explicit instructions for the agent to sanitize or escape external content before it is incorporated into the final artifact's text or generated scripts.
- [DYNAMIC_EXECUTION]: The skill is designed to generate executable HTML and JavaScript to create interactive explanatory models and UI behaviors.
- Script generation: As documented in
references/interactive-html.md, the agent is tasked with implementing JavaScript logic for scenario models, process navigation, and data updates based on the user's subject. - Dynamic assembly: The logic for these interactions is dynamically constructed at runtime based on the specific variables and relationships identified in the user-provided data.
Audit Metadata