ppt-generation
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructions include specific directives that attempt to override the agent's standard behavior of inspecting its tools and environment. Specifically, it instructs the agent "Do NOT read the python file, just call it with the parameters" and "You don't need to check the folder under /mnt/user-data", which limits the agent's ability to verify the code it executes.- [INDIRECT_PROMPT_INJECTION]: The skill facilitates an indirect prompt injection surface by processing untrusted user data into a persistent file format without sanitization.
- Ingestion points: User-provided presentation content, such as titles and key points, is ingested through a JSON plan file in
scripts/generate.py. - Boundary markers: The script does not implement delimiters or security headers when writing this content into the speaker notes of the generated PPTX file.
- Capability inventory: The skill uses the
python-pptxlibrary to write files to the filesystem. - Sanitization: No sanitization or validation logic is present to filter or escape potentially malicious strings within the user-provided content.
Audit Metadata