frontend-slides
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses platform-specific shell commands (open, xdg-open, start) to automatically open generated HTML files in the browser.
- [EXTERNAL_DOWNLOADS]: The skill references the python-pptx library for PowerPoint processing and instructs the agent to ask the user to install it if it is missing.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes text and data from external, untrusted .ppt and .pptx files.
- Ingestion points: Data is ingested from user-provided .ppt and .pptx files during the conversion workflow.
- Boundary markers: No explicit boundary markers or warnings are used to prevent the agent from following instructions embedded within the slide content.
- Capability inventory: The skill can write HTML files to the local filesystem and execute shell commands to open them.
- Sanitization: There is no logic provided to sanitize or filter the content extracted from presentation files before it is used in the generation process.
Audit Metadata