frontend-slides

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The export-pdf.sh script installs the playwright package and downloads the Chromium browser binary from official repositories. These are well-known development tools used here for the specific purpose of rendering slides to PDF.
  • [COMMAND_EXECUTION]: The skill executes various system commands to manage the presentation workflow, including npm for dependency installation, node for running the export logic, and platform-specific openers (open, xdg-open, start) to display the final output to the user.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied content and extracts data from PowerPoint files, creating a surface for indirect prompt injection.
  • Ingestion points: Text and notes are extracted from .pptx files via scripts/extract-pptx.py and interpolated into generated HTML slides.
  • Boundary markers: Not present; content is directly inserted into the HTML template.
  • Capability inventory: The skill has the ability to write files to the local system, execute shell commands, and perform network requests for external fonts.
  • Sanitization: No specific sanitization or validation logic for the extracted slide content was observed in the provided scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — frontend-slides