ppt-visual

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides instructional design guidance and ASCII-based wireframes for presentation slides. The logic is purely descriptive and does not involve executable code or sensitive system access.
  • [EXTERNAL_DOWNLOADS]: The skill recommends several external websites for sourcing design assets such as icons, stock photos, and color palettes.
  • Evidence: References to well-known services including Unsplash, Pexels, The Noun Project, and Adobe Color.
  • Context: These references are informative links to established design tools and do not involve automated downloads or remote script execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing user-supplied presentation content, which creates a potential surface for indirect injection if the content is malicious.
  • Ingestion points: Slide content, purpose, and audience details provided by the user (SKILL.md).
  • Boundary markers: None explicitly defined in the prompts.
  • Capability inventory: The skill is configured to use the create_pptx and md_to_pptx tools from the office-mcp server to generate files.
  • Sanitization: Standard LLM guardrails are assumed; no additional sanitization logic is present in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:38 AM
Security Audit — agent-trust-hub — ppt-visual