docx-to-markdown

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The SKILL.md file includes instructions designed to override agent behavior, such as directives to "Ignore Claude-specific mode-switch instructions" and a "Strict execution contract" requiring the agent to execute the skill protocol exactly as written. These meta-instructions are intended to prioritize the skill's specific rules over the agent's general safety and operational guidelines.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external DOCX files, which creates an indirect prompt injection surface where malicious instructions embedded in a document could influence the agent when it processes the resulting Markdown.
  • Ingestion points: DOCX files are ingested via the --input argument and processed in scripts/lib/converter.cjs.
  • Boundary markers: The conversion output does not include boundary markers or warnings to the agent that the converted content is untrusted data.
  • Capability inventory: The skill utilizes file system write capabilities (fs.writeFileSync) in scripts/lib/converter.cjs and scripts/lib/output-handler.cjs to save Markdown and extracted images.
  • Sanitization: While the skill uses mammoth and turndown for conversion, it does not perform sanitization of the resulting text content to filter for prompt injection patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 06:57 AM
Security Audit — agent-trust-hub — docx-to-markdown