wecomcli-pptx
Warn
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/doc_image_extractor.pyutilizes the__import__()function for dynamic module loading. This is used to handle optional dependencies at runtime, which is a technique that could potentially be exploited to load unauthorized code. - [COMMAND_EXECUTION]: The skill uses
subprocess.run()to execute shell commands, specifically inscripts/pptx2image.pyto invoke LibreOffice (soffice) for file conversion. It also extensively uses thewecom-clicommand-line tool for document operations as defined in the API references. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external documents like PPTX, DOCX, and PDF files. The content extracted from these files is used to generate presentation slides.
- Ingestion points: Document content is processed via
wecom-cli media extractand the provided image extraction scripts. - Boundary markers: The skill contains explicit safety rules in
SKILL.mdthat instruct the agent to detect and neutralize script tags, iframes, and event handlers. - Capability inventory: The skill possesses file system access, shell command execution capabilities, and network access via vendor tools.
- Sanitization: The instructions include a 'Safety Rules' section that mandates checks for malicious patterns like
javascript:protocols and<script>tags before content is written to pages.
Audit Metadata