morph-ppt-3d

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads an installation script and binary for the 'officecli' tool from vendor-owned domains (d.officecli.ai) and the official GitHub repository for the project.
  • [REMOTE_CODE_EXECUTION]: Installation instructions for the required 'officecli' utility involve piping remote scripts directly to a shell interpreter (bash or PowerShell iex).
  • [DYNAMIC_EXECUTION]: The skill utilizes an inline Python script ('python3 -c') to parse JSON search results fetched from the Sketchfab API.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a search flow that ingests data from external 3D model repositories.
  • Ingestion points: API responses from Sketchfab and Poly Pizza (SKILL.md).
  • Boundary markers: None specified for external data.
  • Capability inventory: PowerPoint creation via 'officecli', network downloads via 'curl', and local script execution via 'python3'.
  • Sanitization: The implementation uses standard JSON parsing to extract specific metadata (name, URL, license) rather than executing data as code.
  • [COMMAND_EXECUTION]: The skill generates and executes shell commands for searching, downloading files, and building PowerPoint decks using the 'officecli' command-line interface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 06:56 AM
Security Audit — agent-trust-hub — morph-ppt-3d