agent-mode
Warn
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill configuration explicitly enables 'autoExecute: true'. This setting allows the agent to run generated code blocks automatically, removing the safety barrier of manual user review before execution.- [REMOTE_CODE_EXECUTION]: The instructions direct the agent to 'immediately generate executable JavaScript code' to be run in the 'WPS Plugin Host'. The lack of specific constraints on the types of JavaScript APIs the agent can use increases the risk of the agent being manipulated into performing unintended actions.- [DATA_EXFILTRATION]: Because the skill processes document content and has the ability to execute code, there is a potential risk surface for data exfiltration if the execution environment allows network access. The prompt lacks instructions to sanitize input or restrict the agent's behavior when handling potentially sensitive document data.
Audit Metadata