bid-doc
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to configure Node.js environment variables (NODE_PATH) and launch automation scripts for document generation.\n- [REMOTE_CODE_EXECUTION]: Utilizes script templates for local COM automation of Microsoft Word (win32com) and browser-based rendering (playwright) to generate and modify files at runtime.\n- [EXTERNAL_DOWNLOADS]: Dependencies like playwright involve downloading browser binaries, and the generated HTML reports reference external Font Awesome assets via CDN.\n- [PROMPT_INJECTION]: The skill processes user-supplied technical documents and scoring criteria as primary inputs for document generation. There are no boundary markers or instructions to sanitize these external inputs, creating a surface for indirect prompt injection.
Audit Metadata