ppt-orchestra-skill

Warn

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The compilation script (slides/compile.js) uses require() with dynamic paths to load and execute code from local files based on a naming pattern (e.g., ./slide-${num}.js). This runtime loading of computed paths allows for the execution of code not explicitly defined in the main script.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a QA process that extracts text from generated PowerPoint files using markitdown and feeds it back into the agent's context for review. This creates a feedback loop where untrusted content generated or processed by the skill could influence the agent's behavior.
  • Ingestion points: Output from python -m markitdown output.pptx processed in the verification loop.
  • Boundary markers: None present; the raw text output is reviewed directly by the agent.
  • Capability inventory: File writing (pres.writeFile), package installation (npm, pip), and shell command execution (node, python, grep).
  • Sanitization: None present.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing markitdown (a library from Microsoft) and pptxgenjs (a widely used library for PowerPoint generation). These downloads originate from reputable sources.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 27, 2026, 08:32 AM
Security Audit — agent-trust-hub — ppt-orchestra-skill