pptx

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill provides a robust set of tools for working with Office Open XML formats and found no malicious instructions or prompt injection attempts.
  • [COMMAND_EXECUTION]: The skill executes several system utilities including 'soffice', 'pdftoppm', and 'git' using 'subprocess.run' with list-based arguments. These calls are securely implemented (shell=False) and are necessary for the primary functions of converting slides to PDF/images and validating document integrity.
  • [DATA_EXFILTRATION]: No unauthorized data exfiltration patterns were found. Browser automation via Playwright is used strictly for rendering local HTML files to slide layouts.
  • [PROMPT_INJECTION]: The skill has an inherent attack surface for indirect prompt injection as it reads content from user-provided PPTX files ('scripts/inventory.py'). However, this is a standard risk for document processing tools, and the skill's logic is focused on programmatic data extraction rather than direct obedience to document content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:46 AM
Security Audit — agent-trust-hub — pptx