ppt-editing-skill
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external PowerPoint files (
user-provided.pptx) using themarkitdowntool to extract content into markdown. This content is then used to plan slide mapping and edit XML files, which could allow malicious instructions embedded in a presentation to influence the agent's subsequent actions. - Ingestion points: Files are accessed via
cp /path/to/user-provided.pptx template.pptxand processed usingpython -m markitdown template.pptx. - Boundary markers: The instructions do not specify any delimiters or safety warnings for the agent to ignore potentially malicious instructions embedded in the extracted slide content.
- Capability inventory: The skill has the capability to execute shell commands (
cp,python), modify files on the local filesystem, and invoke anEdittool for XML modifications. - Sanitization: The skill follows security best practices by recommending
defusedxml.minidomfor XML parsing to mitigate XML External Entity (XXE) vulnerabilities, though this does not prevent prompt-based injection. - [EXTERNAL_DOWNLOADS]: The skill relies on external Python modules for its core functionality.
- The instructions reference
python -m markitdownfor content extraction. - The instructions reference the use of
defusedxmlfor secure XML processing.
Audit Metadata