pptx
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: Employs the defusedxml library for XML parsing, which is a standard security practice to prevent XML External Entity (XXE) vulnerabilities.
- [COMMAND_EXECUTION]: Utilizes system-level tools including LibreOffice (soffice) and pdftoppm for legitimate presentation processing tasks like PDF conversion and image generation.
- [EXTERNAL_DOWNLOADS]: Lists necessary dependencies such as playwright, sharp, and markitdown, which are established tools for rendering and document manipulation.
- [PROMPT_INJECTION]: The skill handles external data from user presentations, which presents a surface for indirect prompt injection; however, this is consistent with its purpose and the use of specialized libraries helps ensure safe content handling.
Audit Metadata