template-deck-builder

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/qa_deck.py invokes external command-line utilities soffice (LibreOffice) and pdftoppm (part of poppler) using subprocess.run. These tools are used to render PowerPoint slides into PNG images for visual quality assurance, which is a core feature of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a processing pipeline for user-provided data, specifically storyboard JSON files and PowerPoint templates (.pptx/.potx).
  • Ingestion points: The storyboard JSON file processed by build_deck.py and qa_deck.py, and the PowerPoint template files processed by inspect_template.py and build_deck.py.
  • Boundary markers: The skill enforces a structured JSON schema for all slide content, which acts as a boundary for input data.
  • Capability inventory: The skill performs file system operations for deck generation and invokes rendering tools via shell commands.
  • Sanitization: The skill uses the python-pptx library to map data directly to template placeholders, rather than dynamically evaluating the input strings as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:50 AM
Security Audit — agent-trust-hub — template-deck-builder