skills/astro-han/pawwork/office-docx/Gen Agent Trust Hub

office-docx

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes benign shell commands (mkdir, cp) and runs its validation script through uv run. These actions are confined to the local environment and the skill's own file structure.
  • [EXTERNAL_DOWNLOADS]: The skill depends on the python-docx package from PyPI, managed by uv. This is a trusted, well-known library for document processing.
  • [SAFE]: The skill includes functionality to read existing documents, which constitutes an indirect prompt injection surface. Ingestion point: Document(path) call in SKILL.md. Boundary markers: Absent. Capability inventory: Local file writing and script execution via uv, with no network access or high-privilege operations. Sanitization: Absent. Given the skill's primary purpose and lack of dangerous capabilities, this surface presents minimal risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 07:24 PM
Security Audit — agent-trust-hub — office-docx