doc
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill interacts with external system tools, specifically
soffice(LibreOffice) andpdftoppm(Poppler), to perform document conversion and rendering. - The bundled helper script
scripts/render_docx.pyusessubprocess.run()with the command passed as a list of arguments, which is a recommended security practice to prevent shell injection vulnerabilities. - The
SKILL.mdfile provides shell command templates for manual execution that include shell variables (e.g.,$INPUT_DOCX,$OUTDIR). The security of these commands relies on the agent safely handling variable interpolation during execution. - [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves processing and rendering user-provided
.docxfiles, which presents a surface for indirect prompt injection or the exploitation of vulnerabilities in third-party document parsers. - Ingestion points: The skill accepts and processes
.docxfiles provided by the user via thepython-docxlibrary and the LibreOffice rendering engine. - Boundary markers: The instructions do not define explicit boundaries or warnings for the agent to distinguish between its instructions and the content within the documents it processes.
- Capability inventory: The skill has the capability to read from and write to the file system (specifically in
/tmp/docsandoutput/doc) and execute system commands for document processing. - Sanitization: The skill does not implement specific sanitization or filtering of the content or metadata within the documents before rendering or processing them.
Audit Metadata