gslides-creator
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The Python script
scripts/gslides_creator.pyinvokes shell commands to manage Google Apps Script projects. - Evidence: The
_run_claspfunction usessubprocess.runto executenpx @google/claspfor operations likepush,create, andrun. - Evidence: The script also executes sibling Python tools like
gslides_parser.pyviasubprocess.run. - [EXTERNAL_DOWNLOADS]: The skill triggers the download of the
@google/clasputility from the NPM registry at runtime. - Evidence: Usage of
npx @google/claspinscripts/gslides_creator.pyensures the tool is available from a well-known service (NPM) provided by a trusted organization (Google). - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by interpolating user-provided topics directly into LLM prompts to generate presentation outlines and content.
- Ingestion points: User-supplied
topicandtitlearguments inscripts/gslides_creator.pyflow into Gemini API prompts. - Boundary markers: Prompts in
scripts/outline_adapter.pyandscripts/gslides_creator.pyuse structured headers (e.g.,## ルール) but lack explicit instructions for the model to ignore potential injection attempts within the user input. - Capability inventory: The skill has the ability to create, copy, and modify Google Slides presentations and Google Drive files via the OAuth scopes defined in
gas/appsscript.json. - Sanitization: The skill employs
json.loadsandyaml.safe_loadto process Gemini's output before using it to populate slides via Google Apps Script.
Audit Metadata