pptx-posters
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied JSON manifests and local image assets, creating a surface for indirect prompt injection.
- Ingestion points: Processes
poster.jsonfiles and local PNG/JPEG assets referenced within the manifest in files likescripts/validate_manifest.pyandscripts/inventory_images.py. - Boundary markers: The manifest requires explicit
author_approved: trueandauthor_verified: trueboolean flags for all content; the validator (_manifest.py) contains regex patterns to detect and reject common placeholders (e.g., TODO, REPLACE_ME) and unapproved elements. - Capability inventory: Writing
.pptxfiles to the local filesystem viascripts/generate_poster.pyand executing bundled Python scripts for auditing and generation. - Sanitization: The implementation uses strict schema validation with mandatory keys, strips EXIF and textual metadata from images in
scripts/inventory_images.py, and includes a dedicated security inspector inscripts/inspect_pptx.pythat rejects macros, OLE objects, ActiveX controls, and external relationships in the final package output.
Audit Metadata