skills/4444j99/a-i--skills/docx/Gen Agent Trust Hub

docx

Warn

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/office/soffice.py contains hardcoded C source code that is written to the system temporary directory and compiled into a shared object library (.so) using gcc at runtime.
  • [PRIVILEGE_ESCALATION]: The skill utilizes process injection via the LD_PRELOAD environment variable in scripts/office/soffice.py to inject the compiled shim into the LibreOffice process. This shim is specifically designed to bypass sandbox restrictions that block AF_UNIX sockets by redirecting them to socketpair calls, effectively circumventing environment security controls.
  • [COMMAND_EXECUTION]: Multiple scripts including scripts/office/soffice.py, ooxml/scripts/pack.py, and scripts/accept_changes.py execute shell commands via subprocess.run. These commands include calls to the gcc compiler and the soffice binary with custom environment configurations and macros.
  • [PROMPT_INJECTION]: The SKILL.md file contains explicit instructions directed at the AI agent to override its default behavior, specifically demanding that it "READ ENTIRE FILE" and "NEVER set any range limits" when accessing the skill's documentation files.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted .docx files through external utilities such as pandoc and LibreOffice. The combination of processing complex third-party binary formats and having powerful execution capabilities (like runtime compilation and process injection) creates a large attack surface for potential exploitation via malicious document content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — docx