frontend-slides
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands to interact with the user's environment, including running Python scripts for PowerPoint conversion and utilizing system-native commands like
open,xdg-open, orstartto open the generated HTML files in a browser. - [EXTERNAL_DOWNLOADS]: The skill suggests the installation of the
python-pptxlibrary from the Python Package Index (PyPI) if it is not already available. It also references external font services, such as Google Fonts and Fontshare, for slide typography. - [PROMPT_INJECTION]: As the skill ingests content from external
.pptand.pptxfiles provided by users, there is a theoretical surface for indirect prompt injection if those files contain instructions meant to influence the agent's behavior during the conversion process.
Audit Metadata