docx
Fail
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: HIGHDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The module
scripts/office/soffice.pycontains an embedded C source code string. At runtime, the skill writes this code to a temporary directory, compiles it usinggcc, and then uses theLD_PRELOADenvironment variable to inject the generated shared library (.so) into the LibreOffice (soffice) process. This shims low-level socket functions (socket,listen,accept,close,read) to allow communication in environments where standard UNIX domain sockets are restricted. - [COMMAND_EXECUTION]: The skill frequently invokes external system binaries and compilers.
- It calls
gccto compile its own injection shim. - It executes
soffice(LibreOffice) to perform document conversions and execute macros. - It utilizes
gitfor diffing text content during validation. - It uses standard utilities like
zip,unzip, andpandocfor document processing. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process Word documents from untrusted sources, which exposes a potential attack surface.
- Ingestion points: Document XML content is parsed and processed in multiple scripts, such as
scripts/merge_runs.pyandscripts/office/validators/docx.py. - Boundary markers: While the skill performs XSD schema validation, it does not use explicit boundary delimiters when extracting text for the agent to read.
- Capability inventory: The skill has broad capabilities including file system access (read/write/delete), archive manipulation, and arbitrary shell command execution via subprocesses.
- Sanitization: The skill effectively uses
defusedxmlto prevent XML External Entity (XXE) attacks and performs rigorous schema checks to ensure document integrity.
Recommendations
- AI detected serious security threats
Audit Metadata