skills/whizzzkid/skills/wk-preso/Gen Agent Trust Hub

wk-preso

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches an avatar image from https://avatars.githubusercontent.com/u/1895906?s=64. This targets a well-known service (GitHub) and the resource is used solely for branding purposes within the generated Artifact file.\n- [COMMAND_EXECUTION]: The skill uses the Bash tool to run curl for downloading the image and base64 for encoding it. These are standard operations for embedding assets in self-contained HTML files.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection due to its ingestion of external and user-supplied data.\n
  • Ingestion points: Step 1 gathers content from user-provided topics, outlines, and external research (files or search results).\n
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' warnings to prevent the agent from following instructions embedded in the source content.\n
  • Capability inventory: The agent has access to Write, Bash, and Artifact tools, which could be misused if malicious instructions in the input data are obeyed during the deck generation process.\n
  • Sanitization: There are no explicit instructions to sanitize, validate, or escape the external content before interpolating it into the slide deck.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 09:51 PM
Security Audit — agent-trust-hub — wk-preso