syncfusion-dotnet-powerpoint

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill defines a 'Mode 2' (Execute via CSX Script) that instructs the agent to create a temporary '.csx' file on the host and run it using the 'dotnet script' command. This facilitates the generation and execution of arbitrary code at runtime.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from PowerPoint (.pptx) files, including text, comments, and speaker notes. This data enters the agent's context and could contain malicious instructions. The skill lacks boundary markers or sanitization logic to handle this data safely, while possessing high-impact capabilities like file system modification and command execution.
  • Ingestion points: Processing of external PPTX content via 'Syncfusion.Presentation.Open' and various search/read operations (SKILL.md, find-and-replace.md).
  • Boundary markers: Absent.
  • Capability inventory: Local file writing (pptxDoc.Save), network-based package retrieval (NuGet), and shell command execution (dotnet script).
  • Sanitization: Absent.
  • [REMOTE_CODE_EXECUTION]: The skill's execution templates (template.csx) use NuGet directives to download and execute third-party libraries at runtime. While these libraries are from the vendor Syncfusion, the process of fetching and running external code from public registries during skill execution is a significant capability.
  • [COMMAND_EXECUTION]: The skill explicitly uses the system's shell to execute 'dotnet script' and 'dotnet tool' commands to manage its execution environment and run generated logic.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 01:45 PM
Security Audit — agent-trust-hub — syncfusion-dotnet-powerpoint