docx-manipulation

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs 'python-docx' via pip, which is a well-known, legitimate library from the official Python Package Index for Word document automation.
  • [PROMPT_INJECTION]: An indirect prompt injection surface exists because the skill processes content from external Word documents. 1. Ingestion points: Accesses existing .docx files and uses text extraction tools. 2. Boundary markers: None. 3. Capability inventory: File system read and write operations for document manipulation. 4. Sanitization: No content validation is implemented.
  • [SAFE]: The skill's behavior is consistent with its stated purpose of document manipulation, and no evidence of exfiltration, persistence, or malicious intent was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 07:46 PM
Security Audit — agent-trust-hub — docx-manipulation