skills/atxinsky/skills/bid-doc/Gen Agent Trust Hub

bid-doc

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to configure Node.js environment variables (NODE_PATH) and launch automation scripts for document generation.\n- [REMOTE_CODE_EXECUTION]: Utilizes script templates for local COM automation of Microsoft Word (win32com) and browser-based rendering (playwright) to generate and modify files at runtime.\n- [EXTERNAL_DOWNLOADS]: Dependencies like playwright involve downloading browser binaries, and the generated HTML reports reference external Font Awesome assets via CDN.\n- [PROMPT_INJECTION]: The skill processes user-supplied technical documents and scoring criteria as primary inputs for document generation. There are no boundary markers or instructions to sanitize these external inputs, creating a surface for indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 04:00 PM
Security Audit — agent-trust-hub — bid-doc