pptx
Warn
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/office/soffice.pyperforms runtime compilation of a C source file into a shared object usinggcc. This library is then injected into thesoffice(LibreOffice) process via theLD_PRELOADenvironment variable. The shim intercepts and redirects standard socket operations to enable IPC in environments where Unix domain sockets may be restricted. - [COMMAND_EXECUTION]: Multiple scripts in the skill execute system commands using the
subprocessmodule. Specifically,scripts/thumbnail.pycallssofficeandpdftoppm;ooxml/scripts/pack.pycallssoffice;scripts/office/soffice.pycallsgccandsoffice; andscripts/office/validators/redlining.pycallsgitfor diff operations. - [INDIRECT_PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection attacks by processing untrusted data from user-provided presentation files.
- Ingestion points:
ooxml/scripts/unpack.pyandscripts/inventory.pyextract raw text and XML structure from.pptxarchives. - Boundary markers: Absent. The skill does not implement delimiters or specific instructions to isolate content extracted from slides.
- Capability inventory: The skill can execute shell commands via
subprocess(across multiple scripts) and perform arbitrary file system writes (inscripts/replace.pyandscripts/add_slide.py). - Sanitization: Absent. There is no evidence of filtering or escaping logic applied to data extracted from presentation files before it enters the agent context.
- [EXTERNAL_DOWNLOADS]:
SKILL.mdandhtml2pptx.mdprovide instructions to install several third-party dependencies from public registries includingmarkitdown,pptxgenjs,playwright,react-icons, andsharp.
Audit Metadata