pptx-creator

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/create_pptx.py invokes an external script from a sibling directory (nano-banana-pro/scripts/generate_image.py) using subprocess.run. While the implementation uses a list of arguments which prevents traditional shell injection, it creates a execution dependency on a companion skill that may not be present or could be substituted by a malicious actor in a shared environment.
  • [PROMPT_INJECTION]: The skill exhibits an Indirect Prompt Injection surface. It processes untrusted data from markdown outlines and JSON structures provided by the user (or potentially an external source). Specifically, the parse_outline and main functions in scripts/create_pptx.py extract content following a generate: directive and pass it directly to a downstream image generation process without sanitization or boundary markers to prevent the embedded instructions from being misinterpreted by the receiving agent.
  • Ingestion points: Presentation outlines (.md) and JSON slide definitions processed in scripts/create_pptx.py.
  • Boundary markers: None identified in the prompt templates or processing logic.
  • Capability inventory: Uses subprocess.run to execute local shell commands and scripts; accesses local file system for template storage and temporary image files.
  • Sanitization: None; input strings are stripped but not validated for instructions or escape sequences before being passed to other tools.
  • [CREDENTIALS_SAFE]: The skill follows secure practices for handling sensitive information. In scripts/create_pptx.py, CRM integration credentials (TWENTY_API_TOKEN) are retrieved from environment variables rather than being hardcoded, which is the recommended practice for secret management.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — pptx-creator