pptx
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes system utilities to handle presentation file formats and validation tasks. evidence: \n
scripts/thumbnail.pyexecutessofficefor PDF conversion andpdftoppmfor imaging.\nooxml/scripts/pack.pyusessofficeto verify document integrity during repacking.\nooxml/scripts/validation/redlining.pycallsgitfor diff analysis in tracked changes validation.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a processing surface for untrusted data by parsing user presentations and rendering HTML slides. evidence: \n- Ingestion points:
scripts/inventory.pyextracts text from.pptxfiles, andscripts/html2pptx.jsrenders user-provided HTML.\n - Boundary markers: Instructions do not specify delimiters for content extracted from user presentations, which is a potential surface for indirect injection.\n
- Capability inventory: The skill can execute shell commands and write to the file system.\n
- Sanitization: Implements
defusedxmlfor secure XML parsing in most scripts to prevent XXE, though some validation modules uselxml.\n- [EXTERNAL_DOWNLOADS]: The skill requires several well-known libraries and tools for its operation, all sourced from established registries or official repositories. evidence: \n - Python dependencies:
markitdown,defusedxml,python-pptx,Pillow,lxml,six.\n - Node.js dependencies:
pptxgenjs,playwright,sharp,react-icons,react,react-dom.\n - System tools:
LibreOffice,Poppler, andgit.
Audit Metadata