slides-video
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, untrusted sources including web pages, PDF documents, and source code repositories during the research phase.
- Ingestion points: The research methodology described in
references/research-method.mdutilizesWebFetch,WebSearch, andRead(for PDFs) to gather information from the public internet and user-provided files. - Boundary markers: The instructions do not specify the use of boundary markers or instructions to ignore potential malicious prompts embedded within the gathered research material.
- Capability inventory: The skill has the capability to write files to the local directory, call other agent skills, and execute Javascript in a browser context via developer tools.
- Sanitization: There is no evidence of content sanitization or validation for the data retrieved from external sources before it is interpreted by the agent.
- [COMMAND_EXECUTION]: The skill leverages browser automation tools to execute Javascript for layout auditing purposes.
- Evidence: In
references/overflow-audit.md, the skill provides Javascript snippets to be executed viachrome-devtoolsto detect element overflows and manage slide transitions during the QA process. - [EXTERNAL_DOWNLOADS]: The skill documentation recommends that users install third-party agent skills from external GitHub repositories to provide necessary slide generation capabilities.
- Evidence:
SKILL.mdsuggests the repositoryhttps://github.com/zarazhangrui/frontend-slidesas a resource for the user to install if a slide skill is not already present in the environment.
Audit Metadata