pptx
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [Command Execution] (SAFE): The skill utilizes local Python scripts and system utilities like soffice and pdftoppm for PowerPoint processing. These operations are appropriate for the skill's functional requirements.
- [External Downloads] (SAFE): Dependencies include 'markitdown', 'Pillow', and 'pptxgenjs'. 'markitdown' is maintained by Microsoft, a trusted organization, and the other packages are standard industry tools.
- [Prompt Injection] (LOW): Indirect Prompt Injection Surface. The skill ingests untrusted data from .pptx files and incorporates it into prompts for visual and content QA performed by subagents. 1. Ingestion points: .pptx files via markitdown and image conversion. 2. Boundary markers: Absent in the subagent verification prompts. 3. Capability inventory: Execution of local scripts and system commands (soffice, pdftoppm). 4. Sanitization: No sanitization of extracted presentation content is specified.
Audit Metadata