pptx-posters

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of local Python utilities for poster generation and auditing, which handle file processing and report generation entirely within the user's local environment.\n- [EXTERNAL_DOWNLOADS]: The skill documentation suggests that the agent fetch metadata from ArXiv, a well-known scientific repository, to ensure the accuracy of scientific citations and author records.\n- [INDIRECT_PROMPT_INJECTION]: \n
  • Ingestion points: The skill ingests untrusted data via user-provided JSON manifest files and image assets.\n
  • Boundary markers: The workflow requires manual author approval and content hashing to ensure that all generated content corresponds to verified sources.\n
  • Capability inventory: The included scripts possess the ability to read local files, create PowerPoint presentations, and generate JSON reports.\n
  • Sanitization: The implementation uses strict input validation for text strings and includes custom logic to prevent XML External Entity (XXE) attacks during package inspection by rejecting DTD and entity declarations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:05 AM
Security Audit — agent-trust-hub — pptx-posters