codex-slides-ai-presentation
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
codex-slidesplugin from thenexu-ioorganization on the Codex Marketplace and references external documentation hosted on GitHub. - [REMOTE_CODE_EXECUTION]: The skill utilizes the
@codex-slides/sdkNode.js package and a CLI tool (codex-slides) to programmatically generate and render presentations, which involves executing code locally to handle file exports and rendering logic. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its core functionality of processing external data to generate slide content.
- Ingestion points: The skill reads local Markdown, JSON, YAML, Code, and PDF files, and performs multi-round web research via MCP tools to gather content for slide decks.
- Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat external content as untrusted or to ignore embedded instructions within the ingested data.
- Capability inventory: The agent has the capability to write to the file system (PPTX/PDF exports), perform network research, and execute parallel rendering processes.
- Sanitization: The skill lacks evidence of content sanitization, filtering, or validation before the ingested data is used to generate outlines and visual content.
Audit Metadata