docx-manipulation
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs 'python-docx' via pip, which is a well-known, legitimate library from the official Python Package Index for Word document automation.
- [PROMPT_INJECTION]: An indirect prompt injection surface exists because the skill processes content from external Word documents. 1. Ingestion points: Accesses existing .docx files and uses text extraction tools. 2. Boundary markers: None. 3. Capability inventory: File system read and write operations for document manipulation. 4. Sanitization: No content validation is implemented.
- [SAFE]: The skill's behavior is consistent with its stated purpose of document manipulation, and no evidence of exfiltration, persistence, or malicious intent was found.
Audit Metadata