pptx
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes PowerPoint and HTML files, which represents an indirect prompt injection surface where embedded malicious instructions could target the AI agent behavior.
- Ingestion points: Processes slide content and layout definitions from .pptx XML and HTML source files.
- Boundary markers: No specific instructions are provided to the agent to treat embedded text as untrusted data.
- Capability inventory: The skill can execute CLI tools, launch a headless browser, and manage workspace files.
- Sanitization: Uses defusedxml for secure XML parsing to prevent XXE vulnerabilities.
- [COMMAND_EXECUTION]: The skill executes external command-line utilities using subprocess.run to perform core conversion and validation tasks.
- Evidence: Invokes soffice (LibreOffice), pdftoppm (Poppler), and git for document processing and diffing operations.
Audit Metadata