slide-making-skill

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing dependencies and references external asset sources during slide generation.
  • Evidence: Instructions to install well-known packages via npm install -g react-icons react react-dom sharp for icon processing.
  • Evidence: References to fetching external image assets from example domains like https://example.com/image.jpg within the PptxGenJS tutorial.
  • [COMMAND_EXECUTION]: The skill incorporates a verification step using an external CLI tool to ensure output quality.
  • Evidence: Suggested Quality Assurance loop using python -m markitdown slide-XX-preview.pptx to verify the content of generated PowerPoint files.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a content generation engine, creating a surface for processing untrusted text into a structured output format.
  • Ingestion points: Slide titles, body paragraphs, and chart data provided by the user or agent in SKILL.md and pptxgenjs.md.
  • Boundary markers: The skill does not explicitly define delimiters to separate user-provided text from the slide-generation code structure.
  • Capability inventory: The skill produces executable JavaScript files, generates native .pptx files, and suggests using shell commands for text extraction.
  • Sanitization: No specific sanitization or escaping mechanisms are described for user-provided strings before they are embedded into the generated JavaScript logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:13 AM
Security Audit — agent-trust-hub — slide-making-skill