skills/openai/plugins/google-slides/Gen Agent Trust Hub

google-slides

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Network Operations and External Downloads]: The skill utilizes command-line tools to fetch image data for visual verification. Specifically, it instructs the agent to use curl to download slide thumbnails from URLs provided by the Google Drive connector. This is used to ensure visual fidelity after editing slides. The URLs are generated by trusted platform tools and downloaded to a local temporary directory for inspection.
  • [Indirect Prompt Injection Surface]: The skill processes external data by reading and importing Google Slides presentations and PowerPoint files. This represents a potential surface for indirect prompt injection if the source material contains malicious instructions. The skill mitigates this by enforcing strict 'Release-Blocker Checklists' and 'Non-Negotiable Output Invariants,' which require the agent to perform structural readbacks and visual thumbnail verifications of all changes before completing the task.
  • [Command Execution Environment]: The skill utilizes a node_repl environment for source processing and helper utilities. It also uses shell commands for image verification tasks. These execution paths are scoped to the intended functionality of deck manipulation and quality assurance.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 11:38 AM
Security Audit — agent-trust-hub — google-slides