slide-making-skill
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing dependencies and references external asset sources during slide generation.
- Evidence: Instructions to install well-known packages via
npm install -g react-icons react react-dom sharpfor icon processing. - Evidence: References to fetching external image assets from example domains like
https://example.com/image.jpgwithin the PptxGenJS tutorial. - [COMMAND_EXECUTION]: The skill incorporates a verification step using an external CLI tool to ensure output quality.
- Evidence: Suggested Quality Assurance loop using
python -m markitdown slide-XX-preview.pptxto verify the content of generated PowerPoint files. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a content generation engine, creating a surface for processing untrusted text into a structured output format.
- Ingestion points: Slide titles, body paragraphs, and chart data provided by the user or agent in
SKILL.mdandpptxgenjs.md. - Boundary markers: The skill does not explicitly define delimiters to separate user-provided text from the slide-generation code structure.
- Capability inventory: The skill produces executable JavaScript files, generates native
.pptxfiles, and suggests using shell commands for text extraction. - Sanitization: No specific sanitization or escaping mechanisms are described for user-provided strings before they are embedded into the generated JavaScript logic.
Audit Metadata