pptx

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes system commands via Python's subprocess.run() to perform essential document operations.
  • In ooxml/scripts/pack.py and scripts/thumbnail.py, the soffice (LibreOffice) utility is invoked to convert Office documents to HTML or PDF formats.
  • In scripts/thumbnail.py, pdftoppm is used to rasterize PDF slide pages into JPEG images for visual inspection.
  • In ooxml/scripts/validation/redlining.py, git diff is used to compare text content and validate tracked changes within Word documents.
  • [EXTERNAL_DOWNLOADS]: The skill instructions specify several well-known third-party dependencies required for its functionality.
  • Node.js dependencies include playwright for slide rendering, sharp for image and gradient processing, and pptxgenjs for presentation generation.
  • Python dependencies include markitdown for text extraction and defusedxml for secure XML parsing to mitigate XXE vulnerabilities.
  • [DATA_EXPOSURE_&_EXFILTRATION]: The skill processes structured data from presentation files.
  • Ingestion points: ooxml/scripts/unpack.py and scripts/inventory.py ingest content from Office Open XML (OOXML) files.
  • Capability inventory: The skill has the capability to write files and execute specific system commands for document conversion.
  • Sanitization: The skill implements secure XML parsing using the defusedxml library to prevent common XML-based attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 12:54 PM
Security Audit — agent-trust-hub — pptx