powerpoint
Pass
Audited by Gen Agent Trust Hub on Feb 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute a local script at
src/tools/powerpoint-tool.tsusingts-nodefor PowerPoint generation. - [PROMPT_INJECTION]: The skill ingests user content to create slides, creating a surface for indirect prompt injection.
- Ingestion points: Content is provided through JSON payloads passed as CLI arguments.
- Boundary markers: The documentation does not specify any delimiters to separate instructions from data.
- Capability inventory: The skill relies on
Bash,Read, andWritecapabilities. - Sanitization: No input sanitization is mentioned in the provided documentation.
Audit Metadata