frontend-slides
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses platform-specific commands to open generated HTML files in the default browser:
openfor macOS,xdg-openfor Linux, andstartfor Windows. This is standard behavior for presenting content to the user. - [COMMAND_EXECUTION]: The skill invokes
python3to run extraction scripts for PowerPoint files, which is a routine operation for its conversion functionality. - [EXTERNAL_DOWNLOADS]: The skill requests the installation of the
python-pptxlibrary from the standard Python Package Index (PyPI) to handle slide conversion tasks. - [PROMPT_INJECTION]: The skill processes untrusted external data by ingesting user-supplied notes and content from
.pptor.pptxfiles. While it lacks explicit boundary markers or sanitization for this data, the risk is minimal and inherent to the task of content conversion. - Ingestion points: Reads text and images from user-uploaded
.ppt/.pptxfiles and accepts text drafts (SKILL.md). - Boundary markers: None identified; external content is processed directly for slide generation.
- Capability inventory: Executes shell commands for opening files and runs Python scripts for data processing (SKILL.md).
- Sanitization: No specific sanitization or filtering of the ingested slide content is described.
Audit Metadata