slides-polish
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data from slide decks (PPTX and Beamer LaTeX source) and passes snippets to an external LLM (Codex) to generate layout and typography fixes.
- Ingestion points: Reads content from
*.pptx,*.tex, and*.pdffiles provided by the user. - Boundary markers: While prompt templates are defined, they do not utilize explicit delimiters or specific instructions to the model to ignore potentially malicious instructions embedded within the slide text itself.
- Capability inventory: The skill has access to
Bash,Write, andEdittools, allowing it to modify files and execute Python scripts based on the results of the LLM review. - Sanitization: There is no evidence of sanitization or escaping of slide content before it is interpolated into the prompts for the reviewer agent.
- [DYNAMIC_EXECUTION]: The skill generates and executes local scripts at runtime to perform inspection and apply fixes.
- Evidence: The skill instructions dictate that if
inspect_pptx.pyis missing, the agent should create it based on a provided "contract" (schema and CLI specification) and execute it. - Evidence: The per-page fix loop relies on an LLM generating "concrete python-pptx (or .tex) fixes" which are then applied to the working copy of the document.
- [COMMAND_EXECUTION]: The skill relies on executing various external CLI tools for rendering and conversion.
- Evidence: The workflow involves executing
pdftoppm,mutool,soffice,xelatex, andlatexmkvia shell commands to process the slide data.
Audit Metadata