slides-polish

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data from slide decks (PPTX and Beamer LaTeX source) and passes snippets to an external LLM (Codex) to generate layout and typography fixes.
  • Ingestion points: Reads content from *.pptx, *.tex, and *.pdf files provided by the user.
  • Boundary markers: While prompt templates are defined, they do not utilize explicit delimiters or specific instructions to the model to ignore potentially malicious instructions embedded within the slide text itself.
  • Capability inventory: The skill has access to Bash, Write, and Edit tools, allowing it to modify files and execute Python scripts based on the results of the LLM review.
  • Sanitization: There is no evidence of sanitization or escaping of slide content before it is interpolated into the prompts for the reviewer agent.
  • [DYNAMIC_EXECUTION]: The skill generates and executes local scripts at runtime to perform inspection and apply fixes.
  • Evidence: The skill instructions dictate that if inspect_pptx.py is missing, the agent should create it based on a provided "contract" (schema and CLI specification) and execute it.
  • Evidence: The per-page fix loop relies on an LLM generating "concrete python-pptx (or .tex) fixes" which are then applied to the working copy of the document.
  • [COMMAND_EXECUTION]: The skill relies on executing various external CLI tools for rendering and conversion.
  • Evidence: The workflow involves executing pdftoppm, mutool, soffice, xelatex, and latexmk via shell commands to process the slide data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:08 PM
Security Audit — agent-trust-hub — slides-polish