html-ppt-creator

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to manage the application lifecycle, including installing project dependencies with pnpm and building the production React app. It also executes Python scripts to perform legitimate image processing tasks such as resizing and cropping.
  • [EXTERNAL_DOWNLOADS]: Fetches the well-known Pillow library via pip and retrieves web fonts from established providers like Google Fonts and Fontshare to support presentation aesthetics.
  • [SAFE]: The skill processes external user data in a structured manner. Evidence Chain: 1. Ingestion points: SKILL.md (scanning user-specified image folders). 2. Boundary markers: Present (the skill explicitly asks for outline confirmation before generating code). 3. Capability inventory: SKILL.md (subprocess calls for builds and image manipulation). 4. Sanitization: Absent (the skill relies on the agent's reasoning and the user's manual review of the proposed outline).
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 08:21 PM
Security Audit — agent-trust-hub — html-ppt-creator