frontend-slides
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands to automatically open generated HTML files and PDFs across different operating systems.
- Evidence:
SKILL.mdcontains logic foropen,xdg-open, andstart ""based on the OS. - Evidence:
scripts/export-pdf.shusesnpx,npm install, andnodeto manage the export process. - [EXTERNAL_DOWNLOADS]: The skill performs runtime installations of software and libraries to handle specialized tasks like PDF exporting and image processing.
- Evidence:
scripts/export-pdf.shexecutesnpm install playwrightandnpx playwright install chromiumin a temporary directory. - Evidence:
SKILL.mdandhtml-template.mdsuggest usingpip install python-pptxandpip install Pillowfor content extraction and image optimization. - [REMOTE_CODE_EXECUTION]: The PDF export script generates a temporary Node.js script and executes it using the local Node runtime after installing dependencies.
- Evidence:
scripts/export-pdf.shwrites a complex JavaScript payload (export-slides.mjs) to a temporary directory and runs it withnode. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from PowerPoint files and user-provided notes to generate presentations, creating a path for malicious instructions embedded in the content to influence the agent.
- Ingestion points: PowerPoint (.pptx) files processed by
scripts/extract-pptx.pyand raw text notes pasted by users inSKILL.mdworkflow. - Boundary markers: None detected; instructions imply direct extraction and placement of content into HTML templates.
- Capability inventory: Shell command execution (file openers), file writes (HTML, JSON, images), and network access (dependency installation).
- Sanitization: No explicit sanitization or escaping of extracted slide text or notes is described before interpolation into the
html-template.mdstructures.
Audit Metadata