visual-style-ppt

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it is designed to ingest and process untrusted data from various document formats to generate slide content and image prompts.
  • Ingestion points: references/workflow.md and SKILL.md specify that the skill reads user-provided Markdown, TXT, PDF, Word, and PPT files as content sources.
  • Boundary markers: Analysis of the workflow and prompt templates shows an absence of clear boundary markers or instructions for the agent to disregard malicious commands embedded within the source documents.
  • Capability inventory: The skill has the capability to perform file system operations (saving ZIP files to ~/Downloads and creating directories), call image generation tools, and assemble PPTX files.
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the text extracted from input documents before it is interpolated into subsequent prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 02:58 AM