pptx
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runto interact with system utilities for document processing tasks. Specifically, it callssoffice(LibreOffice) for document validation and conversion inooxml/scripts/pack.pyandscripts/thumbnail.py,pdftoppmfor image generation inscripts/thumbnail.py, andgitfor version comparison inooxml/scripts/validation/redlining.py. - [EXTERNAL_DOWNLOADS]: The setup instructions guide the user to install several standard dependencies from official registries (PyPI and NPM) as well as necessary system-level utilities.
- [SAFE]: The skill utilizes the
defusedxmllibrary for processing XML content inooxml/scripts/unpack.pyandooxml/scripts/pack.py, which is a recognized best practice for mitigating common XML security risks like external entity expansion (XXE).
Audit Metadata