wecomcli-pptx

Warn

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/doc_image_extractor.py utilizes the __import__() function for dynamic module loading. This is used to handle optional dependencies at runtime, which is a technique that could potentially be exploited to load unauthorized code.
  • [COMMAND_EXECUTION]: The skill uses subprocess.run() to execute shell commands, specifically in scripts/pptx2image.py to invoke LibreOffice (soffice) for file conversion. It also extensively uses the wecom-cli command-line tool for document operations as defined in the API references.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external documents like PPTX, DOCX, and PDF files. The content extracted from these files is used to generate presentation slides.
  • Ingestion points: Document content is processed via wecom-cli media extract and the provided image extraction scripts.
  • Boundary markers: The skill contains explicit safety rules in SKILL.md that instruct the agent to detect and neutralize script tags, iframes, and event handlers.
  • Capability inventory: The skill possesses file system access, shell command execution capabilities, and network access via vendor tools.
  • Sanitization: The instructions include a 'Safety Rules' section that mandates checks for malicious patterns like javascript: protocols and <script> tags before content is written to pages.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 24, 2026, 06:24 AM
Security Audit — agent-trust-hub — wecomcli-pptx