skills/jr2804/prompts/pptx/Gen Agent Trust Hub

pptx

Warn

Audited by Gen Agent Trust Hub on May 21, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/soffice.py dynamically writes C source code to a temporary file, compiles it using gcc at runtime, and uses the LD_PRELOAD environment variable to inject the shared library into the soffice process. This is designed to shim socket system calls to allow LibreOffice to run in sandboxed environments.- [COMMAND_EXECUTION]: Multiple scripts, including scripts/thumbnail.py, scripts/soffice.py, and scripts/validators/redlining.py, use the subprocess.run function to execute external system tools such as soffice, pdftoppm, git, and gcc to support presentation rendering and validation.- [SAFE]: The skill uses the defusedxml library for all XML parsing operations, providing robust protection against XML External Entity (XXE) attacks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 21, 2026, 08:51 PM
Security Audit — agent-trust-hub — pptx