pptx-deck-builder
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill automates deck creation and diagram rendering by executing the
pptxandexcalCLI tools with parameters derived from workspace files and user input. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it treats user-supplied YAML content and PowerPoint templates as authoritative sources for generating output. Ingestion points: Untrusted slide content and metadata from user-provided YAML and .pptx files. Boundary markers: The skill instructions do not specify the use of delimiters or provide warnings to the agent to ignore instructions embedded within the input data. Capability inventory: The agent can execute CLI commands and perform filesystem write operations. Sanitization: No validation or sanitization logic is described for the text and data processed during the construction of the presentation.
Audit Metadata