pptx-creator

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/export_to_images.py utilizes subprocess.run to invoke system tools like libreoffice and pdftoppm for converting presentation slides into images. This functionality is part of the --verify feature for automated quality review. The commands are constructed using list-based arguments and resolved file paths, preventing shell injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The skill relies on standard Python libraries (google-genai, python-pptx, pyyaml) and requires system-level tools (libreoffice, poppler-utils) for full functionality. These dependencies are standard for the tool's purpose and are clearly documented in the README.
  • [SAFE]: The skill uses yaml.safe_load in scripts/outline_generator.py and scripts/template_engine.py to handle structured data. This prevents potential remote code execution via unsafe YAML deserialization when processing content generated by the AI model.
  • [SAFE]: Sensitive credentials, specifically Gemini API keys, are correctly managed through environment variables (GEMINI_API_KEY, GOOGLE_API_KEY) rather than being hardcoded within the source files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — pptx-creator