sn-ppt-standard
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses Python's
subprocessmodule and Node.js'sexecSyncto manage the multi-stage pipeline, including coordinating image generation tasks and executing file conversion utilities. These commands are restricted to the skill's internal logic and standard development toolchains. - [EXTERNAL_DOWNLOADS]: To set up its rendering engine, the skill automatically installs required Node.js dependencies via
npmand the Chromium browser viaplaywrightif they are missing from the environment. These downloads originate from trusted, well-known registries and official vendor repositories. - [INDIRECT_PROMPT_INJECTION]: As the pipeline ingests external data from user documents and web search results, it possesses an inherent surface for indirect prompt injection. 1. Ingestion points:
info_pack.json(document excerpts) and web search results enter the agent context. 2. Boundary markers: The skill employs structured JSON schemas and explicit 'language lock' instructions in prompts likepage_html.md. 3. Capability inventory: The skill can execute shell commands viarun_stage.pyfor rendering and exporting. 4. Sanitization: External content is filtered through LLM reasoning stages without secondary code-based validation.
Audit Metadata