Skills pptx
๐Ÿ“ฆ

pptx

Content revision r1 High Risk โš™๏ธ External commands๐Ÿ”‘ Env variables๐ŸŒ Network access๐Ÿ“ Filesystem access

Create and edit PowerPoint presentations

Teams need reliable help creating and updating slide decks without manually editing PPTX internals. This skill gives Claude, Codex, and Claude Code structured workflows for presentation creation, inspection, conversion, and repair.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "pptx" from https://skillstore.io/skills/sickn33-pptx.md and its manifest at https://skillstore.io/api/skills/sickn33-pptx/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "pptx". Create a quarterly business review deck from a short outline.

Expected outcome:

A complete PPTX deck with an agenda, metric slides, risks, recommendations, and speaker notes.

Using "pptx". Review an existing presentation for hidden content and layout problems.

Expected outcome:

  • Slide-by-slide summary
  • Theme and font observations
  • Notes and comments inventory
  • Recommended fixes

Using "pptx". Replace placeholders in a sales deck with updated customer data.

Expected outcome:

An updated presentation with targeted text replacements and the original design structure preserved.

Security Audit

High Risk
v4 โ€ข 7/21/2026 Open versioned report

Most static alerts are false positives caused by OOXML schemas, documentation, JavaScript template literals, and expected presentation file processing. Confirmed concerns are unbounded archive extraction, browser rendering of untrusted HTML, and external conversion of untrusted documents. No prompt injection, credential theft, network reconnaissance, or command-injection behavior was found. Static review was capped at 400/506 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

56
Files scanned
26,504
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (2)

High
Untrusted HTML executes in a browser renderer
The HTML conversion workflow opens a supplied local HTML file in Chromium. Embedded scripts and remote subresources can run or load unless the input is trusted or browser networking is restricted.
The renderer creates a browser page and navigates to the supplied file URL. Browser execution of attacker-provided HTML creates a clear trust-boundary risk.
Medium
External converters process untrusted documents without a timeout
Thumbnail generation sends a supplied presentation to LibreOffice and then sends the produced PDF to Poppler. This exposes local converter parsers to hostile files and can leave stalled processes running.
The documented subprocess calls process supplied office and PDF content. Fixed arguments prevent command injection, but parser exposure and absent time limits remain.
Capability review items (4)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
Archive extract all (zip slip risk)
zipfile.ZipFile(input_file).extractall(output_path)
The workflow extracts an Office archive without member-count or expanded-size limits. A malicious archive can exhaust disk space or processing resources.
High
Archive extract all (zip slip risk)
zip_ref.extractall(temp_path)
The workflow extracts an Office archive without member-count or expanded-size limits. A malicious archive can exhaust disk space or processing resources.
High
Archive extract all (zip slip risk)
zip_ref.extractall(temp_dir)
The workflow extracts an Office archive without member-count or expanded-size limits. A malicious archive can exhaust disk space or processing resources.
High
Archive extract all (zip slip risk)
zip_ref.extractall(temp_path)
The workflow extracts an Office archive without member-count or expanded-size limits. A malicious archive can exhaust disk space or processing resources.

Risk Factors

โš™๏ธ External commands (50)
๐Ÿ”‘ Env variables (4)
๐ŸŒ Network access (50)
ooxml.md:237 ooxml.md:321 ooxml.md:322 ooxml.md:327 ooxml.md:328 ooxml/schemas/ecma/fouth-edition/opc-contentTypes.xsd:2 ooxml/schemas/ecma/fouth-edition/opc-contentTypes.xsd:4 ooxml/schemas/ecma/fouth-edition/opc-coreProperties.xsd:2 ooxml/schemas/ecma/fouth-edition/opc-coreProperties.xsd:3 ooxml/schemas/ecma/fouth-edition/opc-coreProperties.xsd:4 ooxml/schemas/ecma/fouth-edition/opc-coreProperties.xsd:5 ooxml/schemas/ecma/fouth-edition/opc-coreProperties.xsd:7 ooxml/schemas/ecma/fouth-edition/opc-coreProperties.xsd:8 ooxml/schemas/ecma/fouth-edition/opc-coreProperties.xsd:9 ooxml/schemas/ecma/fouth-edition/opc-coreProperties.xsd:10 ooxml/schemas/ecma/fouth-edition/opc-digSig.xsd:2 ooxml/schemas/ecma/fouth-edition/opc-digSig.xsd:4 ooxml/schemas/ecma/fouth-edition/opc-relationships.xsd:2 ooxml/schemas/ecma/fouth-edition/opc-relationships.xsd:4 ooxml/schemas/ISO-IEC29500-4_2016/dml-chart.xsd:3 ooxml/schemas/ISO-IEC29500-4_2016/dml-chart.xsd:4 ooxml/schemas/ISO-IEC29500-4_2016/dml-chart.xsd:5 ooxml/schemas/ISO-IEC29500-4_2016/dml-chart.xsd:6 ooxml/schemas/ISO-IEC29500-4_2016/dml-chart.xsd:7 ooxml/schemas/ISO-IEC29500-4_2016/dml-chart.xsd:8 ooxml/schemas/ISO-IEC29500-4_2016/dml-chart.xsd:10 ooxml/schemas/ISO-IEC29500-4_2016/dml-chart.xsd:12 ooxml/schemas/ISO-IEC29500-4_2016/dml-chart.xsd:14 ooxml/schemas/ISO-IEC29500-4_2016/dml-chart.xsd:16 ooxml/schemas/ISO-IEC29500-4_2016/dml-chartDrawing.xsd:3 ooxml/schemas/ISO-IEC29500-4_2016/dml-chartDrawing.xsd:4 ooxml/schemas/ISO-IEC29500-4_2016/dml-chartDrawing.xsd:5 ooxml/schemas/ISO-IEC29500-4_2016/dml-chartDrawing.xsd:7 ooxml/schemas/ISO-IEC29500-4_2016/dml-diagram.xsd:3 ooxml/schemas/ISO-IEC29500-4_2016/dml-diagram.xsd:4 ooxml/schemas/ISO-IEC29500-4_2016/dml-diagram.xsd:5 ooxml/schemas/ISO-IEC29500-4_2016/dml-diagram.xsd:6 ooxml/schemas/ISO-IEC29500-4_2016/dml-diagram.xsd:7 ooxml/schemas/ISO-IEC29500-4_2016/dml-diagram.xsd:9 ooxml/schemas/ISO-IEC29500-4_2016/dml-diagram.xsd:11 ooxml/schemas/ISO-IEC29500-4_2016/dml-diagram.xsd:13 ooxml/schemas/ISO-IEC29500-4_2016/dml-lockedCanvas.xsd:3 ooxml/schemas/ISO-IEC29500-4_2016/dml-lockedCanvas.xsd:4 ooxml/schemas/ISO-IEC29500-4_2016/dml-lockedCanvas.xsd:5 ooxml/schemas/ISO-IEC29500-4_2016/dml-lockedCanvas.xsd:7 ooxml/schemas/ISO-IEC29500-4_2016/dml-lockedCanvas.xsd:8 ooxml/schemas/ISO-IEC29500-4_2016/dml-main.xsd:3 ooxml/schemas/ISO-IEC29500-4_2016/dml-main.xsd:4 ooxml/schemas/ISO-IEC29500-4_2016/dml-main.xsd:5 ooxml/schemas/ISO-IEC29500-4_2016/dml-main.xsd:6
๐Ÿ“ Filesystem access (50)
ooxml.md:327 ooxml.md:328 ooxml.md:165 ooxml/schemas/ISO-IEC29500-4_2016/wml.xsd:12 ooxml/schemas/microsoft/wml-2010.xsd:3 ooxml/schemas/microsoft/wml-2012.xsd:2 ooxml/schemas/microsoft/wml-2012.xsd:3 ooxml/schemas/microsoft/wml-2018.xsd:2 ooxml/schemas/microsoft/wml-cex-2018.xsd:3 ooxml/schemas/microsoft/wml-cex-2018.xsd:4 ooxml/schemas/microsoft/wml-cid-2016.xsd:2 ooxml/schemas/microsoft/wml-sdtdatahash-2020.xsd:2 ooxml/schemas/microsoft/wml-symex-2015.xsd:2 ooxml/scripts/pack.py:22 ooxml/scripts/pack.py:46 ooxml/scripts/pack.py:13 ooxml/scripts/pack.py:65 ooxml/scripts/pack.py:101 ooxml/scripts/pack.py:154 ooxml/scripts/pack.py:67 ooxml/scripts/pack.py:15 ooxml/scripts/pack.py:76 ooxml/scripts/unpack.py:7 ooxml/scripts/unpack.py:17 ooxml/scripts/unpack.py:17 ooxml/scripts/validate.py:25 ooxml/scripts/validation/base.py:347 ooxml/scripts/validation/base.py:349 ooxml/scripts/validation/base.py:878 ooxml/scripts/validation/base.py:886 ooxml/scripts/validation/base.py:879 ooxml/scripts/validation/base.py:890 ooxml/scripts/validation/base.py:891 ooxml/scripts/validation/docx.py:6 ooxml/scripts/validation/docx.py:198 ooxml/scripts/validation/docx.py:7 ooxml/scripts/validation/docx.py:200 ooxml/scripts/validation/docx.py:201 ooxml/scripts/validation/pptx.py:272 ooxml/scripts/validation/redlining.py:6 ooxml/scripts/validation/redlining.py:64 ooxml/scripts/validation/redlining.py:142 ooxml/scripts/validation/redlining.py:7 ooxml/scripts/validation/redlining.py:69 ooxml/scripts/validation/redlining.py:70 scripts/html2pptx.js:809 scripts/inventory.py:311 scripts/inventory.py:311 scripts/inventory.py:1015 scripts/rearrange.py:160
Audited by: claude View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/sickn33-pptx/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/sickn33-pptx/security.svg)](https://skillstore.io/skills/sickn33-pptx?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/sickn33-pptx?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-pptx/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/sickn33-pptx.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

sickn33. (2026). pptx security audit report (audit version 4) [Author version unspecified]. Skillstore. https://skillstore.io/skills/sickn33-pptx/audits/4

BibTeX citation

@techreport{sickn33-sickn33-pptx-2026, author = {sickn33}, title = {pptx security audit report (audit version 4)}, institution = {Skillstore}, year = {2026}, number = {4}, url = {https://skillstore.io/skills/sickn33-pptx/audits/4}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "pptx security audit report (audit version 4)" version: "unspecified" type: report authors: - name: "sickn33" date-released: "2026-07-21" url: "https://skillstore.io/skills/sickn33-pptx/audits/4" identifiers: - type: other value: "skillstore:sickn33-pptx:audit:4" description: "Skillstore immutable audit report identifier"

Compare variants

12 installable variants

Each author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.

Why this variant is first

Highest Skillstore Score
AutumnsGrove Recommended

autumnsgrove-pptx

Skillstore Score 85
Evidence Confidence High
Skillstore usage 494
Updated

2026-08-21

Skillstore Score 76
Evidence Confidence High
Skillstore usage 258
Updated

2026-08-21

zhanlincui-pptx

Skillstore Score 75
Evidence Confidence High
Skillstore usage 468
Updated

2026-08-21

92bilal26-pptx

Skillstore Score 75
Evidence Confidence High
Skillstore usage 169
Updated

2026-08-21

composiohq-pptx

Skillstore Score 75
Evidence Confidence High
Skillstore usage 42
Updated

2026-08-21

artemisai-pptx

Skillstore Score 75
Evidence Confidence Medium
Skillstore usage 82
Updated

2026-08-21

dyai2025-pptx

Skillstore Score 75
Evidence Confidence Medium
Skillstore usage 25
Updated

2026-08-21

k-dense-ai-pptx

Skillstore Score 74
Evidence Confidence Medium
Skillstore usage 35
Updated

2026-08-21

davila7-pptx

Skillstore Score 74
Evidence Confidence Medium
Skillstore usage 21
Updated

2026-08-21

cam10001110101-pptx

Skillstore Score 50
Evidence Confidence Medium
Skillstore usage 31
Updated

2026-08-21

sickn33 Current

sickn33-pptx

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 24
Updated

2026-08-21

azeem-2-pptx

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 24
Updated

2026-08-21

Skillstore Score

Why this score Evidence Confidence: Medium
45
Architecture
85
Maintainability
87
Content
70
Community
83
Spec Compliance

What You Can Build

Build a client presentation

Create a polished slide deck from an outline, including titles, layouts, speaker notes, and visual hierarchy.

Update an existing deck

Inspect a PPTX file, locate target shapes, replace text or images, and repack the presentation.

Audit presentation structure

Review themes, layouts, comments, notes, relationships, and thumbnails before sharing a deck.

Try These Prompts

Create a simple deck
Create a 6 slide PowerPoint deck about [topic]. Use a clear structure, speaker notes, and a professional visual style.
Analyze an uploaded deck
Analyze this PPTX file. Summarize the slide structure, theme colors, fonts, notes, comments, and layout issues.
Revise a branded presentation
Update this presentation with the new messaging below. Preserve layouts, theme colors, images, and speaker notes where possible.
Validate and repair OOXML
Unpack this PPTX, inspect OOXML relationships and slide references, repair structural issues, then repack and validate the file.

Best Practices

  • Work on copies of presentations before unpacking or replacing internal files.
  • Validate generated decks and inspect thumbnails before sending them to users.
  • Use trusted source files until archive extraction path checks are added.

Avoid

  • Do not process untrusted PPTX files in privileged directories.
  • Do not run setup commands with sudo unless the environment owner approves them.
  • Do not assume HTML rendering will match every PowerPoint feature exactly.

Frequently Asked Questions

Can this skill create new PPTX files?
Yes. It provides an HTML-to-PPTX workflow for slide decks with positioned text, images, shapes, and placeholders.
Can it edit existing presentations?
Yes. It can unpack PPTX files, inspect XML, update content, and repack the Office archive.
Does it support speaker notes and comments?
Yes. The raw XML workflow covers notes slides, modern comments, layouts, themes, and media folders.
Why does it need security review?
Some bundled scripts extract Office archives without path validation and run external converters on presentation files.
Does the skill make network requests?
No active outbound requests were found. Most URLs are OOXML namespace identifiers.
What external dependencies are needed?
Full workflows may need LibreOffice, Poppler, Playwright, pptxgenjs, sharp, markitdown, and defusedxml.

Developer Details

Author

sickn33

License

Proprietary. LICENSE.txt has complete terms

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

816c62b2546ddb1c6a0453e7c781b5e095117819

Maintenance freshness

7/21/2026

Usage

22 downloads ยท 226 views

File structure

๐Ÿ“ ooxml/

๐Ÿ“ schemas/

๐Ÿ“ ecma/

๐Ÿ“ fouth-edition/

๐Ÿ“ ISO-IEC29500-4_2016/

๐Ÿ“„ dml-chart.xsd

๐Ÿ“„ dml-chartDrawing.xsd

๐Ÿ“„ dml-diagram.xsd

๐Ÿ“„ dml-lockedCanvas.xsd

๐Ÿ“„ dml-main.xsd

๐Ÿ“„ dml-picture.xsd

๐Ÿ“„ dml-spreadsheetDrawing.xsd

๐Ÿ“„ dml-wordprocessingDrawing.xsd

๐Ÿ“„ pml.xsd

๐Ÿ“„ shared-additionalCharacteristics.xsd

๐Ÿ“„ shared-bibliography.xsd

๐Ÿ“„ shared-commonSimpleTypes.xsd

๐Ÿ“„ shared-customXmlDataProperties.xsd

๐Ÿ“„ shared-customXmlSchemaProperties.xsd

๐Ÿ“„ shared-documentPropertiesCustom.xsd

๐Ÿ“„ shared-documentPropertiesExtended.xsd

๐Ÿ“„ shared-documentPropertiesVariantTypes.xsd

๐Ÿ“„ shared-math.xsd

๐Ÿ“„ shared-relationshipReference.xsd

๐Ÿ“„ sml.xsd

๐Ÿ“„ vml-main.xsd

๐Ÿ“„ vml-officeDrawing.xsd

๐Ÿ“„ vml-presentationDrawing.xsd

๐Ÿ“„ vml-spreadsheetDrawing.xsd

๐Ÿ“„ vml-wordprocessingDrawing.xsd

๐Ÿ“„ wml.xsd

๐Ÿ“„ xml.xsd

๐Ÿ“ mce/

๐Ÿ“„ mc.xsd

๐Ÿ“ microsoft/

๐Ÿ“„ wml-2010.xsd

๐Ÿ“„ wml-2012.xsd

๐Ÿ“„ wml-2018.xsd

๐Ÿ“„ wml-cex-2018.xsd

๐Ÿ“„ wml-cid-2016.xsd

๐Ÿ“„ wml-sdtdatahash-2020.xsd

๐Ÿ“„ wml-symex-2015.xsd

๐Ÿ“ scripts/

๐Ÿ“ validation/

๐Ÿ“„ __init__.py

๐Ÿ“„ base.py

๐Ÿ“„ docx.py

๐Ÿ“„ pptx.py

๐Ÿ“„ redlining.py

๐Ÿ“„ pack.py

๐Ÿ“„ unpack.py

๐Ÿ“„ validate.py

๐Ÿ“ scripts/

๐Ÿ“„ html2pptx.js

๐Ÿ“„ inventory.py

๐Ÿ“„ rearrange.py

๐Ÿ“„ replace.py

๐Ÿ“„ thumbnail.py

๐Ÿ“„ html2pptx.md

๐Ÿ“„ LICENSE.txt

๐Ÿ“„ ooxml.md

๐Ÿ“„ SKILL.md