skills/andrewhaward2310/.agents/docx/Gen Agent Trust Hub

docx

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Path traversal vulnerability in unpacking utility.
  • Evidence: In ooxml/scripts/unpack.py, the use of zipfile.extractall() without path validation allows for ZipSlip attacks.
  • Risk: Malicious Office documents could potentially overwrite arbitrary files in the agent's environment during the unpacking process.
  • [COMMAND_EXECUTION]: Use of subprocesses for system utilities and validation.
  • Evidence: ooxml/scripts/pack.py and ooxml/scripts/validation/redlining.py execute soffice and git via subprocess.run().
  • Context: These calls are part of the core functionality for document validation and content comparison.
  • [EXTERNAL_DOWNLOADS]: Installation of dependencies from well-known registries.
  • Evidence: SKILL.md lists pandoc, docx, libreoffice, poppler-utils, and defusedxml as required dependencies.
  • Method: Instructions specify using standard system package managers (apt-get, npm, pip) for installation from official repositories.
  • [PROMPT_INJECTION]: Indirect prompt injection attack surface.
  • Ingestion points: Untrusted data enters the agent context via pandoc text extraction and raw XML access from documents provided to the skill.
  • Boundary markers: Absent; there are no specific delimiters or instructions used to isolate extracted document content from the agent's own command logic.
  • Capability inventory: The skill performs subprocess calls, file system writes, and complex document manipulation (as seen in pack.py, document.py, and redlining.py).
  • Sanitization: While defusedxml protects against XML-specific attacks like XXE, the skill lacks mechanisms to sanitize natural language content for potential malicious instructions hidden in processed documents.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 06:20 PM
Security Audit — agent-trust-hub — docx