pptx
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes Office Open XML presentations (.pptx), which are ingested as untrusted external data. The workflow involves converting these documents to markdown or reading their raw XML content to inform the agent's actions. This creates a surface for indirect prompt injection, where malicious content embedded in a presentation could attempt to influence the agent's behavior. The impact is increased by the skill's capabilities to modify files and execute system commands.
- [COMMAND_EXECUTION]: The skill's Python scripts (e.g.,
thumbnail.py,pack.py) execute external shell commands usingsubprocess.run. These commands invoke utilities like LibreOffice (soffice), Poppler (pdftoppm), and Git for document conversion, thumbnail generation, and content validation. Arguments for these commands are constructed from file paths within the workspace. - [DYNAMIC_EXECUTION]: The
html2pptx.jsscript utilizes Playwright to launch a headless browser instance for rendering HTML content. This rendering engine processes local HTML files to calculate positions for PowerPoint slide elements. While used for legitimate layout calculations, a headless browser represents a complex execution environment that handles dynamically generated content.
Audit Metadata