skills/simota/agent-skills/stage/Gen Agent Trust Hub

stage

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data such as specifications, outlines, and learning materials to generate slide decks.
  • Ingestion points: Data enters via user prompts and handoffs from other skills such as Scribe, Tome, and Canvas, as described in the Trigger Guidance in SKILL.md and handoff templates in reference/handoffs.md.
  • Boundary markers: The instructions do not specify explicit delimiters or warnings to ignore instructions embedded within the processed content, which relies on the safety guardrails of the underlying model.
  • Capability inventory: The skill generates Markdown, HTML, and Vue code intended for rendering or execution by external presentation CLI tools.
  • Sanitization: No explicit sanitization or filtering logic is provided in the instructions to handle potentially malicious or adversarial instructions present in the input data.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for using several external tools and references official resources from well-known services.
  • Evidence: References official GitHub repositories for marp-team/marp-cli, hakimel/reveal.js, and slidevjs/slidev in reference/patterns.md.
  • Evidence: Recommends the use of the npx package runner to execute CLI tools from the public NPM registry.
  • Evidence: Includes links to various official documentation sites and third-party rehearsal and presentation services like Gamma, Mermaid.ai, and PromptSmart to assist the user with presentation delivery.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — stage