pptx-toolkit

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install 'python-pptx' via pip. This is a standard, well-known library for PowerPoint manipulation.
  • [DATA_EXPOSURE]: The skill reads from and writes to local PowerPoint files (e.g., 'review.pptx') and accesses local images (e.g., 'chart.png'). This is consistent with its stated purpose and does not involve sensitive system paths or network exfiltration.
  • [INDIRECT_PROMPT_INJECTION]: As the skill is designed to read text and notes from external PowerPoint files, it possesses an ingestion surface for untrusted data. While an attacker could theoretically embed malicious instructions within a presentation's text, the risk is inherent to the task of file processing and the skill does not grant elevated privileges or perform dangerous operations with the extracted content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 01:13 AM
Security Audit — agent-trust-hub — pptx-toolkit