ppt-forge
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process 'original materials' (原始材料) from potentially untrusted sources to generate presentation content and prompts for an external image generation tool.\n
- Ingestion points: Untrusted data enters the agent context during the 'Content Analysis' phase described in
SKILL.md(Step 1) and the 'Content Analysis' section inreferences/ppt-lofi-authoring.md.\n - Boundary markers: The instructions lack explicit delimiting (e.g., XML tags) or 'ignore instructions' warnings for the raw input material, though the workflow mandates multiple human-in-the-loop review steps (such as confirming the 'Paging Plan' and 'Visual Audit') which mitigate but do not eliminate the risk.\n
- Capability inventory: The skill interacts with a host-provided
image-generationtool and writes results to the local file system as raster PNG images.\n - Sanitization: There are no explicit requirements for sanitizing, escaping, or filtering the text extracted from user materials before it is interpolated into blueprints or image generation prompts.
Audit Metadata