frontend-slides
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses platform-specific shell commands (
openon macOS,xdg-openon Linux, andstarton Windows) to automatically open the generated HTML presentation in the user's browser. This is a standard convenience feature for localized document generation tools. - [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the
python-pptxlibrary if it is not present in the environment. This library is a well-known, legitimate dependency required for the skill's PowerPoint conversion functionality. - [DATA_EXFILTRATION]: The skill is designed to read local files (
.pptand.pptx) for the purpose of content extraction and conversion. This access is limited to the conversion workflow and the data is used to generate the local HTML output. - [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it incorporates untrusted data from user-supplied notes and converted PowerPoint files directly into generated HTML and JavaScript code.
- Ingestion points: User-provided notes, slide content, and data extracted from
.pptor.pptxfiles (SKILL.md). - Boundary markers: There are no explicit instructions for the agent to use delimiters or safety guards when interpolating user content into code.
- Capability inventory: The skill performs file system writes, executes shell commands for file opening, and runs Python scripts (SKILL.md).
- Sanitization: The skill does not mention specific sanitization, escaping, or validation steps for content processed during the conversion or enhancement workflows.
Audit Metadata