skills/mrgoonie/claudekit-skills/pptx/Gen Agent Trust Hub

pptx

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes system utilities to handle presentation file formats and validation tasks. evidence: \n
  • scripts/thumbnail.py executes soffice for PDF conversion and pdftoppm for imaging.\n
  • ooxml/scripts/pack.py uses soffice to verify document integrity during repacking.\n
  • ooxml/scripts/validation/redlining.py calls git for diff analysis in tracked changes validation.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a processing surface for untrusted data by parsing user presentations and rendering HTML slides. evidence: \n
  • Ingestion points: scripts/inventory.py extracts text from .pptx files, and scripts/html2pptx.js renders user-provided HTML.\n
  • Boundary markers: Instructions do not specify delimiters for content extracted from user presentations, which is a potential surface for indirect injection.\n
  • Capability inventory: The skill can execute shell commands and write to the file system.\n
  • Sanitization: Implements defusedxml for secure XML parsing in most scripts to prevent XXE, though some validation modules use lxml.\n- [EXTERNAL_DOWNLOADS]: The skill requires several well-known libraries and tools for its operation, all sourced from established registries or official repositories. evidence: \n
  • Python dependencies: markitdown, defusedxml, python-pptx, Pillow, lxml, six.\n
  • Node.js dependencies: pptxgenjs, playwright, sharp, react-icons, react, react-dom.\n
  • System tools: LibreOffice, Poppler, and git.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:16 AM
Security Audit — agent-trust-hub — pptx