frontend-slides
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends the installation of the
python-pptxlibrary to enable PowerPoint file conversion functionality. Users should ensure the package is retrieved from a secure, official registry. - [COMMAND_EXECUTION]: The skill uses operating system commands (
open,xdg-open, andstart) to automatically open generated HTML presentations. If a user-supplied name for the presentation is used in the filename without proper sanitization, it could lead to potential command injection. - [PROMPT_INJECTION]: The conversion of external
.pptand.pptxfiles introduces an indirect prompt injection surface. Maliciously crafted source files could contain instructions designed to manipulate the agent's behavior during the extraction and generation process. - Ingestion points: PowerPoint files (.ppt, .pptx) processed via the
python-pptxlibrary. - Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within source presentation data.
- Capability inventory: The skill possesses the ability to write files to the local system, execute shell commands to open files, and perform package installations.
- Sanitization: There are no documented steps for sanitizing or validating text extracted from source PowerPoint files before it is used in the final HTML output.
Audit Metadata