slide-creator

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMPERSISTENCECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PERSISTENCE]: The script scripts/export_pdf.py modifies the workspace startup file located at /data/workspace/setup.sh. It appends commands to install Python dependencies and the Chromium browser, ensuring they are available upon every environment restart.
  • [COMMAND_EXECUTION]: The scripts/export_pdf.py utility uses subprocess.run to execute the Playwright installation command for Chromium.
  • [INDIRECT_PROMPT_INJECTION]: The skill's Art Direction workflow (defined in SKILL.md and references/art-direction.md) ingests data from external URLs via web_fetch to determine visual styles. This creates a surface where untrusted content could influence the agent's behavior during CSS generation.
  • Ingestion points: Data fetched from user-provided URLs in SKILL.md.
  • Boundary markers: Instructions are provided to ignore branding and focus on tone, but no technical delimiters are used for the external data.
  • Capability inventory: The skill can execute shell commands and perform file system writes.
  • Sanitization: None detected; the skill relies on natural language instructions for filtering.
  • [EXTERNAL_DOWNLOADS]: The skill installs the playwright and PyMuPDF packages and downloads the Chromium browser binaries to facilitate the PDF export process.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 03:33 AM
Security Audit — agent-trust-hub — slide-creator