frontend-slides

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands to automatically open generated HTML files and PDFs across different operating systems.
  • Evidence: SKILL.md contains logic for open, xdg-open, and start "" based on the OS.
  • Evidence: scripts/export-pdf.sh uses npx, npm install, and node to manage the export process.
  • [EXTERNAL_DOWNLOADS]: The skill performs runtime installations of software and libraries to handle specialized tasks like PDF exporting and image processing.
  • Evidence: scripts/export-pdf.sh executes npm install playwright and npx playwright install chromium in a temporary directory.
  • Evidence: SKILL.md and html-template.md suggest using pip install python-pptx and pip install Pillow for content extraction and image optimization.
  • [REMOTE_CODE_EXECUTION]: The PDF export script generates a temporary Node.js script and executes it using the local Node runtime after installing dependencies.
  • Evidence: scripts/export-pdf.sh writes a complex JavaScript payload (export-slides.mjs) to a temporary directory and runs it with node.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from PowerPoint files and user-provided notes to generate presentations, creating a path for malicious instructions embedded in the content to influence the agent.
  • Ingestion points: PowerPoint (.pptx) files processed by scripts/extract-pptx.py and raw text notes pasted by users in SKILL.md workflow.
  • Boundary markers: None detected; instructions imply direct extraction and placement of content into HTML templates.
  • Capability inventory: Shell command execution (file openers), file writes (HTML, JSON, images), and network access (dependency installation).
  • Sanitization: No explicit sanitization or escaping of extracted slide text or notes is described before interpolation into the html-template.md structures.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — frontend-slides