gslides-creator

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The Python script scripts/gslides_creator.py invokes shell commands to manage Google Apps Script projects.
  • Evidence: The _run_clasp function uses subprocess.run to execute npx @google/clasp for operations like push, create, and run.
  • Evidence: The script also executes sibling Python tools like gslides_parser.py via subprocess.run.
  • [EXTERNAL_DOWNLOADS]: The skill triggers the download of the @google/clasp utility from the NPM registry at runtime.
  • Evidence: Usage of npx @google/clasp in scripts/gslides_creator.py ensures the tool is available from a well-known service (NPM) provided by a trusted organization (Google).
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by interpolating user-provided topics directly into LLM prompts to generate presentation outlines and content.
  • Ingestion points: User-supplied topic and title arguments in scripts/gslides_creator.py flow into Gemini API prompts.
  • Boundary markers: Prompts in scripts/outline_adapter.py and scripts/gslides_creator.py use structured headers (e.g., ## ルール) but lack explicit instructions for the model to ignore potential injection attempts within the user input.
  • Capability inventory: The skill has the ability to create, copy, and modify Google Slides presentations and Google Drive files via the OAuth scopes defined in gas/appsscript.json.
  • Sanitization: The skill employs json.loads and yaml.safe_load to process Gemini's output before using it to populate slides via Google Apps Script.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — gslides-creator