ppt-generator
Pass
Audited by Gen Agent Trust Hub on May 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill correctly utilizes environment variables (XF_PPT_APP_ID and XF_PPT_API_SECRET) for API authentication, avoiding the risk of hardcoded credentials.
- [PROMPT_INJECTION]: The instructions include a mandatory input optimization step, requiring users to compress topics into formal report-style titles. This acts as a sanitization layer that prevents raw user input from directly reaching the execution script, mitigating indirect prompt injection risks.
- [COMMAND_EXECUTION]: The skill invokes a local Python script (scripts/index.py) to perform its core task. This is a standard and expected execution pattern for this type of automation skill.
- [SAFE]: The homepage URL points to a well-known and legitimate enterprise AI service provider (iFLYTEK).
Audit Metadata