pptx-analyzer
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/analyze_pptx.pyexecutes external binaries usingsubprocess.run. It specifically attempts to locate and runsoffice(LibreOffice) orlibreofficefor PDF conversion, andqlmanageon macOS for image generation. These calls use a list of arguments rather than a shell string, which is a security best practice that helps prevent command injection vulnerabilities. - [EXTERNAL_DOWNLOADS]: When the
--with-geminiflag is used, the skill sends extracted slide text and images to the Google Gemini API for analysis. This is a documented feature and requires a user-providedGEMINI_API_KEYorGOOGLE_API_KEYto be set in the environment variables. - [DATA_EXFILTRATION]: While the skill processes local PowerPoint files and can send data to the Gemini API, it does not show any signs of unauthorized data exfiltration. The communication is limited to the official Google Generative AI service as part of its intended functionality.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PowerPoint files and interpolates extracted text directly into prompts sent to an LLM (Gemini). While there is a potential for a malicious file to contain instructions designed to manipulate the analysis results, the impact is low as it only affects the output of that specific analysis task.
Audit Metadata