pitch-deck-creation

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the execution of a bundled Python script, scripts/create_pitch_deck.py, to generate presentation files and suggests the installation of the python-pptx library via pip3. These are standard and transparent operations for a document-generation skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface for untrusted data by collecting company and product details from the user to populate the pitch deck content.
  • Ingestion points: User-provided information gathered according to instructions in SKILL.md.
  • Boundary markers: No specific delimiters or warnings to ignore embedded instructions are provided for the gathered data.
  • Capability inventory: The skill writes .pptx files to the local file system using the python-pptx library in the scripts/create_pitch_deck.py script.
  • Sanitization: The input data is parsed as JSON and inserted into document slides without specific validation or sanitization of the text content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:18 AM
Security Audit — agent-trust-hub — pitch-deck-creation