skills/4444j99/a-i--skills/pptx/Gen Agent Trust Hub

pptx

Warn

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/office/soffice.py performs runtime compilation of a C source file into a shared object using gcc. This library is then injected into the soffice (LibreOffice) process via the LD_PRELOAD environment variable. The shim intercepts and redirects standard socket operations to enable IPC in environments where Unix domain sockets may be restricted.
  • [COMMAND_EXECUTION]: Multiple scripts in the skill execute system commands using the subprocess module. Specifically, scripts/thumbnail.py calls soffice and pdftoppm; ooxml/scripts/pack.py calls soffice; scripts/office/soffice.py calls gcc and soffice; and scripts/office/validators/redlining.py calls git for diff operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection attacks by processing untrusted data from user-provided presentation files.
  • Ingestion points: ooxml/scripts/unpack.py and scripts/inventory.py extract raw text and XML structure from .pptx archives.
  • Boundary markers: Absent. The skill does not implement delimiters or specific instructions to isolate content extracted from slides.
  • Capability inventory: The skill can execute shell commands via subprocess (across multiple scripts) and perform arbitrary file system writes (in scripts/replace.py and scripts/add_slide.py).
  • Sanitization: Absent. There is no evidence of filtering or escaping logic applied to data extracted from presentation files before it enters the agent context.
  • [EXTERNAL_DOWNLOADS]: SKILL.md and html2pptx.md provide instructions to install several third-party dependencies from public registries including markitdown, pptxgenjs, playwright, react-icons, and sharp.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — pptx