ingest-slide-templates
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using user-provided strings for file paths and template names without explicit sanitization requirements.
- The commands
unzip -l "<source.pptx>"andnpm run cli -- ingest --source "<source.pptx>" --template "<template-name>"interpolate variables directly into a shell environment. A malicious user or an adversarial file path (e.g.,"; touch /tmp/pwned; #.pptx) could lead to arbitrary command execution. - [INDIRECT_PROMPT_INJECTION]: The skill ingests content from external
.pptxfiles and processes them through a description workflow, creating a surface for indirect prompt injection. - Ingestion points: Content is extracted from user-supplied
.pptxfiles and text fields withinSKILL.mdsteps. - Boundary markers: No delimiters or instructions to ignore embedded commands are present in the prompt instructions.
- Capability inventory: The skill possesses the capability to execute shell commands via
npmand write to the local filesystem in thetemplates/directory. - Sanitization: No sanitization, escaping, or validation of the slide content is mentioned before the data is passed to the description generation workflow.
Audit Metadata