pptx-creator
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/create_pptx.pyinvokes an external script from a sibling directory (nano-banana-pro/scripts/generate_image.py) usingsubprocess.run. While the implementation uses a list of arguments which prevents traditional shell injection, it creates a execution dependency on a companion skill that may not be present or could be substituted by a malicious actor in a shared environment. - [PROMPT_INJECTION]: The skill exhibits an Indirect Prompt Injection surface. It processes untrusted data from markdown outlines and JSON structures provided by the user (or potentially an external source). Specifically, the
parse_outlineandmainfunctions inscripts/create_pptx.pyextract content following agenerate:directive and pass it directly to a downstream image generation process without sanitization or boundary markers to prevent the embedded instructions from being misinterpreted by the receiving agent. - Ingestion points: Presentation outlines (
.md) and JSON slide definitions processed inscripts/create_pptx.py. - Boundary markers: None identified in the prompt templates or processing logic.
- Capability inventory: Uses
subprocess.runto execute local shell commands and scripts; accesses local file system for template storage and temporary image files. - Sanitization: None; input strings are stripped but not validated for instructions or escape sequences before being passed to other tools.
- [CREDENTIALS_SAFE]: The skill follows secure practices for handling sensitive information. In
scripts/create_pptx.py, CRM integration credentials (TWENTY_API_TOKEN) are retrieved from environment variables rather than being hardcoded, which is the recommended practice for secret management.
Audit Metadata