pptx
Warn
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/office/soffice.pyimplements runtime C compilation and library injection. It contains a hardcoded C source string that is written to a temporary file and compiled into a shared object usinggcc. This library is then preloaded into thesoffice(LibreOffice) process via theLD_PRELOADenvironment variable to shim network socket system calls. This is used to ensure compatibility with restricted sandbox environments but employs high-privilege execution techniques. - [COMMAND_EXECUTION]: The skill makes extensive use of the
subprocessmodule to execute external binaries, includinggccfor runtime compilation,sofficefor document conversion,pdftoppmfor image processing, andgitfor document diffing. While these operations appear legitimate for the skill's purpose, they provide a broad capability surface for the agent. - [INDIRECT_PROMPT_INJECTION]: The skill extracts text and structured data from user-provided PowerPoint (.pptx and .potx) files, which are processed by the agent. This creates a surface for indirect prompt injection if the source files contain hidden instructions.
- Ingestion points: Content is extraction from presentation XML files using
markitdownand custom scripts within thescripts/directory. - Boundary markers: The extracted content is not encapsulated with specific instructions or delimiters to isolate it from the agent's operational logic.
- Capability inventory: The skill possesses significant capabilities, including the ability to read and write files, execute subprocesses, and perform runtime compilation and library injection.
- Sanitization: The skill mitigates common XML-based attacks (such as XXE) by consistently utilizing the
defusedxmllibrary for all XML parsing operations.
Audit Metadata