pptx
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's instructions and scripts were thoroughly analyzed, and no malicious patterns, data exfiltration, or safety bypass attempts were identified.
- [COMMAND_EXECUTION]: Local system utilities including LibreOffice (
soffice), Poppler (pdftoppm), andgitare used for essential file processing tasks such as PPTX-to-PDF conversion, slide-to-image rendering, and content diffing. These operations use safe, structured argument lists and represent standard functionality for this utility. - [EXTERNAL_DOWNLOADS]: All external dependencies, such as
playwright,sharp,pptxgenjs, andmarkitdown, are reputable packages from official NPM and PyPI registries. These are standard tools for the skill's design and rendering workflows. - [DYNAMIC_EXECUTION]: The skill uses Playwright to render design layouts in a local headless browser environment, which is a legitimate requirement for calculating element positions during HTML-to-PowerPoint conversion.
- [SAFE]: Security-conscious implementation is evident in the use of the
defusedxmllibrary for all Office Open XML parsing tasks, mitigating risks associated with XML External Entity (XXE) vulnerabilities.
Audit Metadata