docx-to-markdown
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The
SKILL.mdfile includes instructions designed to override agent behavior, such as directives to "Ignore Claude-specific mode-switch instructions" and a "Strict execution contract" requiring the agent to execute the skill protocol exactly as written. These meta-instructions are intended to prioritize the skill's specific rules over the agent's general safety and operational guidelines. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external DOCX files, which creates an indirect prompt injection surface where malicious instructions embedded in a document could influence the agent when it processes the resulting Markdown.
- Ingestion points: DOCX files are ingested via the
--inputargument and processed inscripts/lib/converter.cjs. - Boundary markers: The conversion output does not include boundary markers or warnings to the agent that the converted content is untrusted data.
- Capability inventory: The skill utilizes file system write capabilities (
fs.writeFileSync) inscripts/lib/converter.cjsandscripts/lib/output-handler.cjsto save Markdown and extracted images. - Sanitization: While the skill uses
mammothandturndownfor conversion, it does not perform sanitization of the resulting text content to filter for prompt injection patterns.
Audit Metadata