docx
Warn
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/office/soffice.pycontains hardcoded C source code that is written to the system temporary directory and compiled into a shared object library (.so) usinggccat runtime. - [PRIVILEGE_ESCALATION]: The skill utilizes process injection via the
LD_PRELOADenvironment variable inscripts/office/soffice.pyto inject the compiled shim into the LibreOffice process. This shim is specifically designed to bypass sandbox restrictions that blockAF_UNIXsockets by redirecting them tosocketpaircalls, effectively circumventing environment security controls. - [COMMAND_EXECUTION]: Multiple scripts including
scripts/office/soffice.py,ooxml/scripts/pack.py, andscripts/accept_changes.pyexecute shell commands viasubprocess.run. These commands include calls to thegcccompiler and thesofficebinary with custom environment configurations and macros. - [PROMPT_INJECTION]: The
SKILL.mdfile contains explicit instructions directed at the AI agent to override its default behavior, specifically demanding that it "READ ENTIRE FILE" and "NEVER set any range limits" when accessing the skill's documentation files. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted
.docxfiles through external utilities such aspandocandLibreOffice. The combination of processing complex third-party binary formats and having powerful execution capabilities (like runtime compilation and process injection) creates a large attack surface for potential exploitation via malicious document content.
Audit Metadata