NYC

presentation-builder

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION] (SAFE): The ooxml/scripts/pack.py script uses subprocess.run to call the soffice (LibreOffice) binary for headless document validation. The call is implemented using a list of arguments without shell interpolation, which is a secure and appropriate use of the command execution capability for this skill's purpose.\n- [DATA_EXFILTRATION] (SAFE): All file operations are confined to the paths provided as command-line arguments. No network activity, sensitive environment variable access, or credential harvesting patterns were detected.\n- [REMOTE_CODE_EXECUTION] (SAFE): The skill does not perform any remote code downloads or dynamic execution of external scripts.\n- [PROMPT_INJECTION] (SAFE): No instructions or patterns designed to override agent behavior or bypass safety guardrails were found within the provided scripts or metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:34 PM