docx
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses
defusedxmlfor all XML parsing operations, which protects against common XML vulnerabilities such as XML External Entity (XXE) attacks. - [COMMAND_EXECUTION]: The skill executes external commands like
soffice(LibreOffice) andgitfor document validation and diffing. These are implemented usingsubprocess.runwith argument lists, which prevents shell injection vulnerabilities. - [EXTERNAL_DOWNLOADS]: The documentation provides standard installation instructions for common tools like
pandocandlibreofficevia official package registries. - [PROMPT_INJECTION]: The skill includes instructions to read full documentation files without range limits to ensure the AI agent has the complete context for its API, which is a benign functional requirement.
Audit Metadata