ppt-forge

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process 'original materials' (原始材料) from potentially untrusted sources to generate presentation content and prompts for an external image generation tool.\n
  • Ingestion points: Untrusted data enters the agent context during the 'Content Analysis' phase described in SKILL.md (Step 1) and the 'Content Analysis' section in references/ppt-lofi-authoring.md.\n
  • Boundary markers: The instructions lack explicit delimiting (e.g., XML tags) or 'ignore instructions' warnings for the raw input material, though the workflow mandates multiple human-in-the-loop review steps (such as confirming the 'Paging Plan' and 'Visual Audit') which mitigate but do not eliminate the risk.\n
  • Capability inventory: The skill interacts with a host-provided image-generation tool and writes results to the local file system as raster PNG images.\n
  • Sanitization: There are no explicit requirements for sanitizing, escaping, or filtering the text extracted from user materials before it is interpolated into blueprints or image generation prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:15 PM
Security Audit — agent-trust-hub — ppt-forge