NYC

cinematic-slides

Pass

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection (LOW): The skill processes untrusted user input to drive a multi-stage automated pipeline that includes code generation and external deployment.\n
  • Ingestion points: User input fields for Topic, Audience, and Language used in Step 1.\n
  • Boundary markers: None; user input is passed directly to the presentation-architect skill without delimiters to isolate it from system instructions.\n
  • Capability inventory: The pipeline has the ability to generate HTML/JS code, create media assets via AI, deploy files to GitHub Pages, and send external messages via WhatsApp.\n
  • Sanitization: No validation or escaping is performed on user-provided strings before they are interpolated into the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 19, 2026, 06:38 PM