powerpoint
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes several local scripts (
html2pptx.js,scripts/thumbnail.py,scripts/rearrange.py, andscripts/replace.py) to perform PowerPoint operations. These scripts are invoked with specific arguments to generate thumbnails, rearrange slides, and inject text content, which is consistent with the skill's stated purpose. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data, such as converting reports into presentations or auditing existing decks. While this creates a surface for indirect prompt injection from untrusted files, the instructions do not include any patterns that attempt to bypass safety filters or execute malicious commands based on that data.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill instructions manage slide content and layout locally and do not contain any network operations or instructions to exfiltrate data to external domains.
Audit Metadata