docx
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The SKILL.md file contains instructions to install system-level dependencies such as pandoc, libreoffice, and poppler-utils using sudo apt-get install. The use of sudo allows for administrative privilege acquisition on the host system.
- [COMMAND_EXECUTION]: Python scripts within the skill (ooxml/scripts/pack.py and ooxml/scripts/validation/redlining.py) execute shell commands using subprocess.run(). Specifically, they invoke soffice for document conversion/validation and git diff for comparing document versions. While these calls use parameterized arguments, they represent a capability for system command execution.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and interpret untrusted Word document data. 1. Ingestion points: Untrusted data enters the agent context through document conversion to markdown via pandoc (SKILL.md) and XML unpacking via ooxml/scripts/unpack.py. 2. Boundary markers: No explicit boundary markers or warnings to ignore embedded instructions are used when document content is interpolated into the agent context. 3. Capability inventory: The skill provides scripts that can execute system commands (soffice, git) and modify the local file system. 4. Sanitization: While the skill uses defusedxml to mitigate XML-based attacks during parsing, the natural language content extracted from documents is not filtered or sanitized against adversarial instructions.
Audit Metadata