NYC
skills/smithery/ai/pptx/Gen Agent Trust Hub

pptx

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [Command Execution] (SAFE): The skill utilizes local Python scripts and system utilities like soffice and pdftoppm for PowerPoint processing. These operations are appropriate for the skill's functional requirements.
  • [External Downloads] (SAFE): Dependencies include 'markitdown', 'Pillow', and 'pptxgenjs'. 'markitdown' is maintained by Microsoft, a trusted organization, and the other packages are standard industry tools.
  • [Prompt Injection] (LOW): Indirect Prompt Injection Surface. The skill ingests untrusted data from .pptx files and incorporates it into prompts for visual and content QA performed by subagents. 1. Ingestion points: .pptx files via markitdown and image conversion. 2. Boundary markers: Absent in the subagent verification prompts. 3. Capability inventory: Execution of local scripts and system commands (soffice, pdftoppm). 4. Sanitization: No sanitization of extracted presentation content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:03 PM