pptx-deck

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill follows a workflow where the agent writes a TypeScript file (build.ts) to the filesystem and then executes it using npm run cli. While the script follows a template, it incorporates user-supplied strings into code variables, which is a form of dynamic code generation and execution.
  • [COMMAND_EXECUTION]: The skill utilizes several shell commands to perform its tasks, including node --version for environment checking, find for template discovery, and npm run for building and executing the deck generator.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted data from a user (described as a 'brief', 'narrative', 'notes', or 'raw content') and use it to populate fields in a generated TypeScript file. A malicious brief could attempt to break out of string literals in the generated code to execute arbitrary logic.
  • Ingestion points: User-supplied brief, narrative, or notes (referenced in the 'Workflow' section of SKILL.md).
  • Boundary markers: The instructions suggest using a md() helper for markdown content but do not provide specific guidance on sanitizing quotes or escaping characters to prevent script injection.
  • Capability inventory: The skill has the capability to write files to the local disk and execute shell commands/Node.js scripts.
  • Sanitization: No explicit sanitization or validation steps are defined for the user-supplied text before it is interpolated into the build.ts script.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:07 AM
Security Audit — agent-trust-hub — pptx-deck