pitch-deck
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a utility for structuring and generating business presentations. It follows a transparent workflow of data collection, structured storage in JSON, and document generation using local scripts. No obfuscation or suspicious behavior was identified.
- [COMMAND_EXECUTION]: The skill uses grep to search its own reference documentation and python3 to execute the local generation script. These commands are scoped to the skill's directory and do not process unsanitized external inputs in a way that allows for shell injection.
- [EXTERNAL_DOWNLOADS]: The documentation recommends the installation of python-pptx, which is a standard and reputable library for PowerPoint automation. There are no attempts to download or execute unverified remote scripts or binaries.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface where user-provided text for the pitch deck is processed. While this is an entry point for untrusted data, the impact is limited to the content of a static PowerPoint file and does not result in agent behavior override. (Ingestion points: User-supplied business details in pitch_data.json; Boundary markers: None; Capability inventory: python3 execution and file system write for .pptx output; Sanitization: Handled by the python-pptx library during text insertion)
Audit Metadata