pptx

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted slide content by extracting text for agent analysis, which could contain malicious instructions.
  • Ingestion points: scripts/inventory.py extracts text from all shapes on all slides into JSON; markitdown is also used for text extraction.
  • Boundary markers: Extracted text is provided to the agent without boundary markers or instructions to disregard embedded commands.
  • Capability inventory: The skill includes scripts capable of writing files (ooxml/scripts/pack.py, scripts/replace.py) and executing system commands (scripts/thumbnail.py).
  • Sanitization: Extracted text is not sanitized for prompt injection patterns. While defusedxml is used in some scripts, other components use standard lxml or ElementTree parsers on untrusted presentation XML.
  • [COMMAND_EXECUTION]: Multiple scripts invoke system tools via subprocess.run to perform necessary document conversions.
  • scripts/thumbnail.py and ooxml/scripts/pack.py use soffice (LibreOffice) to convert presentations.
  • scripts/thumbnail.py uses pdftoppm (Poppler) to generate slide images.
  • ooxml/scripts/validation/redlining.py uses git diff for revision tracking.
  • Although these calls use safe argument lists, they represent a significant capability surface if the agent is manipulated by malicious input.
  • [DYNAMIC_EXECUTION]: scripts/html2pptx.js performs dynamic rendering of agent-generated HTML.
  • It utilizes playwright to render slides in a browser environment and executes JavaScript via page.evaluate() to calculate layout coordinates and element dimensions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:20 AM
Security Audit — agent-trust-hub — pptx