ai-ppt-powerpoint-generator

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides template curl and npx commands in the documentation. These allow users to manually interact with the https://agent.deepnlp.org API. These are standard implementation examples and do not execute automatically.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data via the prompt and brief_inputs parameters to generate visual content. While this creates a potential surface for indirect injection, it is the primary intended function of the generator and follows standard usage patterns.
  • Ingestion points: User-supplied prompt and design_config.brief_inputs in the API request body.
  • Boundary markers: Not present in the example payloads.
  • Capability inventory: Network operations via curl and npx (SKILL.md).
  • Sanitization: None documented; the skill relies on the backend API for content filtering.
  • [CREDENTIALS_SAFE]: The skill requires an API key (DEEPNLP_ONEKEY_ROUTER_ACCESS) provided via an environment variable. The documentation correctly instructs users to use a placeholder, which is a best practice for secret management.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 01:55 PM
Security Audit — agent-trust-hub — ai-ppt-powerpoint-generator