slideshow
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs the agent to perform remote updates and download component blocks using the
npx hyperframesCLI tool. Additionally, it provides code examples that import the Three.js library from the established jsDelivr CDN. - [COMMAND_EXECUTION]: Several operations involve executing local shell commands via the
npx hyperframesutility for tasks such as component search, skill updates, linting, and starting a local presenter server. The update process includes an explicit instruction for the agent to obtain user confirmation before execution. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of content from external Figma URLs and third-party web pages to generate slides. This capability introduces a standard attack surface for indirect prompt injection from the source material. Evidence Chain: 1. Ingestion points: Figma URLs and source pages being converted (identified in SKILL.md). 2. Boundary markers: The output is constrained by a specific JSON island schema and HTML scene structure. 3. Capability inventory: File system writes for deck creation, execution of CLI commands, and network access for searching and adding components. 4. Sanitization: The skill explicitly mentions SVG sanitization and brand token binding as part of the Figma import process to mitigate risks from external assets.
Audit Metadata