pptx-posters

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied JSON manifests and local image assets, creating a surface for indirect prompt injection.
  • Ingestion points: Processes poster.json files and local PNG/JPEG assets referenced within the manifest in files like scripts/validate_manifest.py and scripts/inventory_images.py.
  • Boundary markers: The manifest requires explicit author_approved: true and author_verified: true boolean flags for all content; the validator (_manifest.py) contains regex patterns to detect and reject common placeholders (e.g., TODO, REPLACE_ME) and unapproved elements.
  • Capability inventory: Writing .pptx files to the local filesystem via scripts/generate_poster.py and executing bundled Python scripts for auditing and generation.
  • Sanitization: The implementation uses strict schema validation with mandatory keys, strips EXIF and textual metadata from images in scripts/inventory_images.py, and includes a dedicated security inspector in scripts/inspect_pptx.py that rejects macros, OLE objects, ActiveX controls, and external relationships in the final package output.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — pptx-posters