skills/hk-hub/agentskills/pptx/Gen Agent Trust Hub

pptx

Warn

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/office/soffice.py implements a compatibility shim by writing C source code to a temporary file and compiling it with gcc into a shared library. It then uses the LD_PRELOAD environment variable to inject this library into the soffice process at runtime. While documented as a fix for sandboxed environments, runtime compilation and injection are high-risk behaviors.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-supplied files, presenting a vector for indirect prompt injection.\n
  • Ingestion points: Text content is extracted via markitdown and visual previews are generated by scripts/thumbnail.py as described in SKILL.md.\n
  • Boundary markers: The skill relies on XML-style comments in markitdown output to delimit slide boundaries.\n
  • Capability inventory: Scripts execute several system tools including soffice, pdftoppm, git, and zip.\n
  • Sanitization: XML processing throughout the skill (e.g., in scripts/office/validate.py) utilizes defusedxml to protect against XML External Entity (XXE) attacks.\n- [EXTERNAL_DOWNLOADS]: SKILL.md contains instructions for the agent to install packages such as pptxgenjs and sharp from the public npm registry if they are not preinstalled in the environment.\n- [COMMAND_EXECUTION]: Multiple scripts invoke system utilities via subprocess.run. Examples include pdftoppm in scripts/thumbnail.py and git in scripts/office/validators/redlining.py.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 2, 2026, 03:44 AM
Security Audit — agent-trust-hub — pptx