pptx
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted slide content by extracting text for agent analysis, which could contain malicious instructions.
- Ingestion points:
scripts/inventory.pyextracts text from all shapes on all slides into JSON;markitdownis also used for text extraction. - Boundary markers: Extracted text is provided to the agent without boundary markers or instructions to disregard embedded commands.
- Capability inventory: The skill includes scripts capable of writing files (
ooxml/scripts/pack.py,scripts/replace.py) and executing system commands (scripts/thumbnail.py). - Sanitization: Extracted text is not sanitized for prompt injection patterns. While
defusedxmlis used in some scripts, other components use standardlxmlorElementTreeparsers on untrusted presentation XML. - [COMMAND_EXECUTION]: Multiple scripts invoke system tools via
subprocess.runto perform necessary document conversions. scripts/thumbnail.pyandooxml/scripts/pack.pyusesoffice(LibreOffice) to convert presentations.scripts/thumbnail.pyusespdftoppm(Poppler) to generate slide images.ooxml/scripts/validation/redlining.pyusesgit difffor revision tracking.- Although these calls use safe argument lists, they represent a significant capability surface if the agent is manipulated by malicious input.
- [DYNAMIC_EXECUTION]:
scripts/html2pptx.jsperforms dynamic rendering of agent-generated HTML. - It utilizes
playwrightto render slides in a browser environment and executes JavaScript viapage.evaluate()to calculate layout coordinates and element dimensions.
Audit Metadata