pptx
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill provides a robust set of tools for working with Office Open XML formats and found no malicious instructions or prompt injection attempts.
- [COMMAND_EXECUTION]: The skill executes several system utilities including 'soffice', 'pdftoppm', and 'git' using 'subprocess.run' with list-based arguments. These calls are securely implemented (shell=False) and are necessary for the primary functions of converting slides to PDF/images and validating document integrity.
- [DATA_EXFILTRATION]: No unauthorized data exfiltration patterns were found. Browser automation via Playwright is used strictly for rendering local HTML files to slide layouts.
- [PROMPT_INJECTION]: The skill has an inherent attack surface for indirect prompt injection as it reads content from user-provided PPTX files ('scripts/inventory.py'). However, this is a standard risk for document processing tools, and the skill's logic is focused on programmatic data extraction rather than direct obedience to document content.
Audit Metadata