office
Pass
Audited by Gen Agent Trust Hub on Apr 4, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill defines a standard workflow for an AI agent to generate and execute TypeScript scripts. This includes using
npm installto manage dependencies andnpx tsxto run the generation logic. These operations are essential for the skill's primary purpose of programmatic document creation. - [EXTERNAL_DOWNLOADS]: The skill utilizes well-known, trusted libraries from the npm registry, including
docx,xlsx,pdf-lib, andpptxgenjs. The providedverify-deps.shscript and agent instructions facilitate the installation of these standard packages. - [REMOTE_CODE_EXECUTION]: The workflow involves the dynamic creation of temporary TypeScript files (e.g., in
/tmp/) which are then executed locally. This is a common pattern for document generation tools and does not involve downloading or executing unverifiable code from untrusted remote sources.
Audit Metadata