pptx
Warn
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/office/soffice.pyimplements a compatibility shim by writing C source code to a temporary file and compiling it withgccinto a shared library. It then uses theLD_PRELOADenvironment variable to inject this library into thesofficeprocess at runtime. While documented as a fix for sandboxed environments, runtime compilation and injection are high-risk behaviors.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-supplied files, presenting a vector for indirect prompt injection.\n - Ingestion points: Text content is extracted via
markitdownand visual previews are generated byscripts/thumbnail.pyas described inSKILL.md.\n - Boundary markers: The skill relies on XML-style comments in
markitdownoutput to delimit slide boundaries.\n - Capability inventory: Scripts execute several system tools including
soffice,pdftoppm,git, andzip.\n - Sanitization: XML processing throughout the skill (e.g., in
scripts/office/validate.py) utilizesdefusedxmlto protect against XML External Entity (XXE) attacks.\n- [EXTERNAL_DOWNLOADS]:SKILL.mdcontains instructions for the agent to install packages such aspptxgenjsandsharpfrom the public npm registry if they are not preinstalled in the environment.\n- [COMMAND_EXECUTION]: Multiple scripts invoke system utilities viasubprocess.run. Examples includepdftoppminscripts/thumbnail.pyandgitinscripts/office/validators/redlining.py.
Audit Metadata