docx
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Path traversal vulnerability in unpacking utility.
- Evidence: In
ooxml/scripts/unpack.py, the use ofzipfile.extractall()without path validation allows for ZipSlip attacks. - Risk: Malicious Office documents could potentially overwrite arbitrary files in the agent's environment during the unpacking process.
- [COMMAND_EXECUTION]: Use of subprocesses for system utilities and validation.
- Evidence:
ooxml/scripts/pack.pyandooxml/scripts/validation/redlining.pyexecutesofficeandgitviasubprocess.run(). - Context: These calls are part of the core functionality for document validation and content comparison.
- [EXTERNAL_DOWNLOADS]: Installation of dependencies from well-known registries.
- Evidence:
SKILL.mdlistspandoc,docx,libreoffice,poppler-utils, anddefusedxmlas required dependencies. - Method: Instructions specify using standard system package managers (
apt-get,npm,pip) for installation from official repositories. - [PROMPT_INJECTION]: Indirect prompt injection attack surface.
- Ingestion points: Untrusted data enters the agent context via
pandoctext extraction and raw XML access from documents provided to the skill. - Boundary markers: Absent; there are no specific delimiters or instructions used to isolate extracted document content from the agent's own command logic.
- Capability inventory: The skill performs subprocess calls, file system writes, and complex document manipulation (as seen in
pack.py,document.py, andredlining.py). - Sanitization: While
defusedxmlprotects against XML-specific attacks like XXE, the skill lacks mechanisms to sanitize natural language content for potential malicious instructions hidden in processed documents.
Audit Metadata