pptx-deck
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill follows a workflow where the agent writes a TypeScript file (
build.ts) to the filesystem and then executes it usingnpm run cli. While the script follows a template, it incorporates user-supplied strings into code variables, which is a form of dynamic code generation and execution. - [COMMAND_EXECUTION]: The skill utilizes several shell commands to perform its tasks, including
node --versionfor environment checking,findfor template discovery, andnpm runfor building and executing the deck generator. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted data from a user (described as a 'brief', 'narrative', 'notes', or 'raw content') and use it to populate fields in a generated TypeScript file. A malicious brief could attempt to break out of string literals in the generated code to execute arbitrary logic.
- Ingestion points: User-supplied brief, narrative, or notes (referenced in the 'Workflow' section of SKILL.md).
- Boundary markers: The instructions suggest using a
md()helper for markdown content but do not provide specific guidance on sanitizing quotes or escaping characters to prevent script injection. - Capability inventory: The skill has the capability to write files to the local disk and execute shell commands/Node.js scripts.
- Sanitization: No explicit sanitization or validation steps are defined for the user-supplied text before it is interpolated into the
build.tsscript.
Audit Metadata