pptx-html-fidelity-audit
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from untrusted external sources (PPTX and HTML files) to perform audits. This architecture creates a surface where instructions embedded within the slide content could potentially influence the agent's behavior.
- Ingestion points: The agent analyzes extracted content from
.pptxfiles and reads source.htmlslide decks. - Boundary markers: The instructions do not explicitly include delimiters or warnings to ignore instructions that might be embedded in the processed slide content.
- Capability inventory: The agent can execute local Python scripts (
extract_pptx.py,verify_layout.py) and perform local file read/write operations. - Sanitization: The skill does not perform sanitization or validation of the text content extracted from the slides before the agent processes it.
- [EXTERNAL_DOWNLOADS]: The skill references standard external dependencies and font resources required for its primary task.
- Evidence: Instructions in
SKILL.mdandscripts/extract_pptx.pymention installing thepython-pptxlibrary via the standardpipregistry. - Evidence:
references/font-discipline.mdincludes examples of installing fonts such asNoto Serif TCusingbrewor other system package managers. These are documented as necessary requirements for ensuring font fidelity. - [SAFE]: Analysis of the included Python scripts confirms they are focused on geometric and typographic property extraction. No evidence of network operations, credential harvesting, or unauthorized system modifications was found.
Audit Metadata