pptx

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection attacks by ingesting untrusted content from user-provided PowerPoint files.
  • Ingestion points: Presentation text and metadata are extracted from user-provided files using the markitdown library and custom parsing logic in scripts/inventory.py and ooxml/scripts/unpack.py.
  • Boundary markers: Absent. The skill instructions do not include specific delimiters or warnings for the agent to ignore instructions found within extracted presentation content.
  • Capability inventory: The skill can execute shell commands via subprocess.run (found in scripts/thumbnail.py, ooxml/scripts/pack.py, and ooxml/scripts/validation/redlining.py) and can run dynamically generated JavaScript code using node. It also performs extensive file system operations.
  • Sanitization: While it uses defusedxml for secure XML parsing to prevent XXE, no sanitization is applied to the extracted text content before it is processed by the agent.
  • [COMMAND_EXECUTION]: Several Python scripts invoke external system utilities to handle document conversion and validation tasks.
  • scripts/thumbnail.py executes soffice (from LibreOffice) and pdftoppm (from Poppler) to create visual slide previews.
  • ooxml/scripts/pack.py uses soffice to validate the integrity of repacked Office files.
  • ooxml/scripts/validation/redlining.py uses git diff to compare text content and track changes.
  • These calls use argument lists which mitigate shell injection, but they remain a significant capability surface.
  • [DYNAMIC_EXECUTION]: The workflow for creating new presentations from scratch requires the agent to generate and execute custom JavaScript code.
  • Instructions in SKILL.md provide a template for a Node.js script that the agent must write and execute to build presentations using the provided html2pptx library and the pptxgenjs package.
  • This dynamic code execution is essential for the skill's functionality but increases the potential impact of a successful prompt injection attack.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:10 AM
Security Audit — agent-trust-hub — pptx