pptx

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes system-level commands to perform document conversions and visual validations. It invokes 'soffice' (LibreOffice) to convert presentations to PDF or HTML formats and 'pdftoppm' to generate slide images. These operations are restricted to local file processing and are essential for the skill's documented workflows.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes content from external PowerPoint and HTML files, which represents an ingestion surface for potential indirect prompt injection attacks. However, the risk is addressed through the use of the 'defusedxml' library for secure XML parsing, and the skill's logic is primarily focused on structural and text transformations.\n- [DYNAMIC_EXECUTION]: During the presentation creation process, the skill uses a browser environment (Playwright) to render HTML slides. This is used specifically for calculating element coordinates and layout properties. No evidence of unauthorized network requests or untrusted code execution within the browser environment was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:11 PM
Security Audit — agent-trust-hub — pptx