sn-ppt-standard

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses Python's subprocess module and Node.js's execSync to manage the multi-stage pipeline, including coordinating image generation tasks and executing file conversion utilities. These commands are restricted to the skill's internal logic and standard development toolchains.
  • [EXTERNAL_DOWNLOADS]: To set up its rendering engine, the skill automatically installs required Node.js dependencies via npm and the Chromium browser via playwright if they are missing from the environment. These downloads originate from trusted, well-known registries and official vendor repositories.
  • [INDIRECT_PROMPT_INJECTION]: As the pipeline ingests external data from user documents and web search results, it possesses an inherent surface for indirect prompt injection. 1. Ingestion points: info_pack.json (document excerpts) and web search results enter the agent context. 2. Boundary markers: The skill employs structured JSON schemas and explicit 'language lock' instructions in prompts like page_html.md. 3. Capability inventory: The skill can execute shell commands via run_stage.py for rendering and exporting. 4. Sanitization: External content is filtered through LLM reasoning stages without secondary code-based validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:40 AM
Security Audit — agent-trust-hub — sn-ppt-standard