pptx-generator
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The workflow requires the agent to dynamically generate standalone executable JavaScript files for individual slides and compile them using a master script executed via Node.js. If content extracted from user inputs or presentations is interpolated directly into these template strings without strict escaping, it could enable code injection into the runtime environment.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes an indirect prompt injection attack surface. It ingests external, untrusted presentation files using the markitdown library to extract text and analyze layout structure. No boundary markers or instructions are provided to filter out potential adversarial commands embedded in user files. The capability inventory includes file writing and script execution, which creates a risk if malicious instructions are parsed and obeyed.
- [EXTERNAL_DOWNLOADS]: The configuration documents installation steps for several external package dependencies from public registries without specifying fixed version constraints or integrity pins, which introduces a minor dependency management vulnerability.
Audit Metadata