slide-creator
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMPERSISTENCECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PERSISTENCE]: The script
scripts/export_pdf.pymodifies the workspace startup file located at/data/workspace/setup.sh. It appends commands to install Python dependencies and the Chromium browser, ensuring they are available upon every environment restart. - [COMMAND_EXECUTION]: The
scripts/export_pdf.pyutility usessubprocess.runto execute the Playwright installation command for Chromium. - [INDIRECT_PROMPT_INJECTION]: The skill's Art Direction workflow (defined in
SKILL.mdandreferences/art-direction.md) ingests data from external URLs viaweb_fetchto determine visual styles. This creates a surface where untrusted content could influence the agent's behavior during CSS generation. - Ingestion points: Data fetched from user-provided URLs in
SKILL.md. - Boundary markers: Instructions are provided to ignore branding and focus on tone, but no technical delimiters are used for the external data.
- Capability inventory: The skill can execute shell commands and perform file system writes.
- Sanitization: None detected; the skill relies on natural language instructions for filtering.
- [EXTERNAL_DOWNLOADS]: The skill installs the
playwrightandPyMuPDFpackages and downloads the Chromium browser binaries to facilitate the PDF export process.
Audit Metadata