pitch-deck

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use soffice (LibreOffice) and pdftoppm for headless conversion of PowerPoint files to images. This is a legitimate utility for visual validation of document output in a CLI environment.
  • [DATA_INJECTION]: The skill involves processing external data sources (Excel, CSV, PDF, Word). While this introduces a potential surface for indirect prompt injection, the instructions focus strictly on numerical data extraction and mapping to structured slide templates, which provides natural constraints against adversarial text instructions in the source files.
  • [REMOTE_CODE_EXECUTION]: The skill references the use of python-pptx for programmatic PowerPoint manipulation. All provided code patterns and XML snippets are for local file modification and structure verification, with no evidence of remote script fetching or execution from untrusted sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:20 PM
Security Audit — agent-trust-hub — pitch-deck