gslides-parser
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The Python script 'scripts/gslides_parser.py' uses the subprocess.run method to execute the Google Apps Script CLI tool (clasp). The command is constructed using a list of arguments rather than a raw shell string, which effectively prevents command injection vulnerabilities from user-supplied presentation IDs.\n- [EXTERNAL_DOWNLOADS]: The skill documentation and setup routines utilize 'npx' to run the '@google/clasp' utility. This downloads the tool from the public NPM registry, which is a well-known and trusted service for development tools.\n- [SAFE]: The Google Apps Script manifest 'gas/appsscript.json' requests the 'script.external_request' OAuth scope. While this capability allows the script to make outbound network requests, the provided code in 'gas/parseSlides.js' only interacts with internal Google Slides and Drive APIs to extract presentation data and does not perform any external communication.
Audit Metadata