Impress
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data and files which may contain malicious instructions.
- Ingestion points: The
generate_from_templatefunction inSKILL.mdingests content via thetemplate_pathandcontentdictionary. - Boundary markers: The implementation lacks explicit delimiters or instructions to the agent to ignore embedded commands within the processed files.
- Capability inventory: The skill includes functions that call
subprocess.runto execute system utilities likezip,unzip, andsoffice(SKILL.md). - Sanitization: There is no evidence of input validation or sanitization before the data is interpolated into the presentation's
content.xmlfile. - [COMMAND_EXECUTION]: The skill relies on executing system-level commands through Python's
subprocess.runmodule to handle presentation file manipulation (zipping/unzipping) and conversion via thesofficebinary. While the use of argument lists mitigates shell injection, this remains a significant capability that interacts directly with the host environment.
Audit Metadata