pptx-creator

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/create_pptx.py uses subprocess.run to call an external script (generate_image.py from the nano-banana-pro skill). The prompt argument for this command is taken directly from the user-provided outline or JSON structure without sanitization or validation. While it uses a list for the command arguments to mitigate shell injection, passing unvalidated user data to another executable remains a security risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (Markdown and JSON) to generate presentation content, creating a surface for indirect prompt injection attacks.
  • Ingestion points: Untrusted data enters the agent context through the --outline and --json file arguments processed by scripts/create_pptx.py and scripts/use_template.py.
  • Boundary markers: The skill does not implement boundary markers or specific instructions to the agent to ignore potentially malicious commands embedded within the slide content or image prompts.
  • Capability inventory: The skill has the capability to write files to the local system (creating .pptx files) and execute subprocesses via uv run.
  • Sanitization: There is no evidence of sanitization, escaping, or schema validation for the input data before it is used to generate presentation content or passed to the image generation tool.
  • [DATA_EXPOSURE]: The script scripts/create_pptx.py is configured to access sensitive environment variables, specifically TWENTY_API_TOKEN and TWENTY_API_URL, for CRM data integration. While these are managed via the environment, accessing credentials in a script that processes untrusted external input increases the risk profile if the script were to be exploited.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — pptx-creator