ingest-slide-templates

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using user-provided strings for file paths and template names without explicit sanitization requirements.
  • The commands unzip -l "<source.pptx>" and npm run cli -- ingest --source "<source.pptx>" --template "<template-name>" interpolate variables directly into a shell environment. A malicious user or an adversarial file path (e.g., "; touch /tmp/pwned; #.pptx) could lead to arbitrary command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests content from external .pptx files and processes them through a description workflow, creating a surface for indirect prompt injection.
  • Ingestion points: Content is extracted from user-supplied .pptx files and text fields within SKILL.md steps.
  • Boundary markers: No delimiters or instructions to ignore embedded commands are present in the prompt instructions.
  • Capability inventory: The skill possesses the capability to execute shell commands via npm and write to the local filesystem in the templates/ directory.
  • Sanitization: No sanitization, escaping, or validation of the slide content is mentioned before the data is passed to the description generation workflow.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 07:07 AM
Security Audit — agent-trust-hub — ingest-slide-templates