ralphthon-seoul-mid-presentation-en

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the slides-grab package from the npm registry and the Chromium browser via Playwright. These are standard dependencies required for the tool's operation and are sourced from well-known registries.- [COMMAND_EXECUTION]: The workflow involves running local CLI commands including slides-grab validate, slides-grab build-viewer, and slides-grab edit within a workspace directory. These commands are necessary for the skill's primary purpose of creating and reviewing presentation slides.- [PROMPT_INJECTION]: No evidence of direct prompt injection, safety filter bypasses, or instructions to override system prompts were detected in the skill's files.- [DATA_EXFILTRATION]: The skill manages data within a local decks/ directory and does not contain instructions to access sensitive environment variables, credentials, or system paths, nor does it perform unauthorized network requests.- [PROMPT_INJECTION]: The skill processes user-provided information from an interview (defined in references/interview-checklist.md) to generate slide content. While it lacks explicit boundary markers for this untrusted data, its capabilities are restricted to the slide generation toolset, which aligns with its intended use case. Ingestion points: User interview inputs gathered in SKILL.md. Boundary markers: Absent. Capability inventory: Local CLI execution of slides-grab commands and file writes to the decks/ directory. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:55 AM