skills/iofficeai/officecli/morph-ppt/Gen Agent Trust Hub

morph-ppt

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The SKILL.md file provides setup instructions that involve downloading and executing a remote installation script (e.g., curl -fsSL https://d.officecli.ai/install.sh | bash). These resources are hosted on the vendor's domain (officecli.ai) for the specific tool the skill supports.
  • [COMMAND_EXECUTION]: The skill includes Python and Bash helper scripts (reference/morph-helpers.py and reference/morph-helpers.sh) that wrap officecli functionality. The Python script uses subprocess.run with list-based arguments and performs type validation on numeric parameters to prevent shell injection.
  • [EXTERNAL_DOWNLOADS]: The skill references the vendor's official GitHub repository (https://github.com/iOfficeAI/OfficeCLI/releases) as a source for downloading the required command-line tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a mandatory 'Delivery Gate' process to validate the generated output. Specifically, 'Gate 2 morph' uses regex to audit slide text for accidental shell variable expansion or token leaks, providing a layer of protection when incorporating user-provided content into the deck.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:53 AM
Security Audit — agent-trust-hub — morph-ppt