whiteboard-to-infographic

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • Dynamic Execution: The skill generates Python code at runtime to construct PowerPoint slides using the python-pptx library.
  • The logic utilizes deterministic coordinate calculations based on predefined templates to ensure layout consistency.
  • Code execution is performed within the agent's local environment, utilizing standard libraries to produce the final .pptx file.
  • Indirect Prompt Injection Surface: As the skill ingests and processes user-provided images, it incorporates external data into its execution flow.
  • Ingestion points: The process begins with the ingestion of whiteboard photos or sketches provided by the user (SKILL.md).
  • Boundary markers: A verification phase is mandated, where the agent must present the transcribed content to the user for approval before generating the slide (SKILL.md, Step 2).
  • Capability inventory: The agent possesses the ability to write and execute Python scripts to generate files within its container (references/network-map.md).
  • Sanitization: Manual human review serves as a primary validation step to ensure that the data being processed matches the intended source and is free from unwanted instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 11:56 PM
Security Audit — agent-trust-hub — whiteboard-to-infographic