ppt-editing-skill

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external PowerPoint files (user-provided.pptx) using the markitdown tool to extract content into markdown. This content is then used to plan slide mapping and edit XML files, which could allow malicious instructions embedded in a presentation to influence the agent's subsequent actions.
  • Ingestion points: Files are accessed via cp /path/to/user-provided.pptx template.pptx and processed using python -m markitdown template.pptx.
  • Boundary markers: The instructions do not specify any delimiters or safety warnings for the agent to ignore potentially malicious instructions embedded in the extracted slide content.
  • Capability inventory: The skill has the capability to execute shell commands (cp, python), modify files on the local filesystem, and invoke an Edit tool for XML modifications.
  • Sanitization: The skill follows security best practices by recommending defusedxml.minidom for XML parsing to mitigate XML External Entity (XXE) vulnerabilities, though this does not prevent prompt-based injection.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external Python modules for its core functionality.
  • The instructions reference python -m markitdown for content extraction.
  • The instructions reference the use of defusedxml for secure XML processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:32 AM
Security Audit — agent-trust-hub — ppt-editing-skill