doc

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill interacts with external system tools, specifically soffice (LibreOffice) and pdftoppm (Poppler), to perform document conversion and rendering.
  • The bundled helper script scripts/render_docx.py uses subprocess.run() with the command passed as a list of arguments, which is a recommended security practice to prevent shell injection vulnerabilities.
  • The SKILL.md file provides shell command templates for manual execution that include shell variables (e.g., $INPUT_DOCX, $OUTDIR). The security of these commands relies on the agent safely handling variable interpolation during execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves processing and rendering user-provided .docx files, which presents a surface for indirect prompt injection or the exploitation of vulnerabilities in third-party document parsers.
  • Ingestion points: The skill accepts and processes .docx files provided by the user via the python-docx library and the LibreOffice rendering engine.
  • Boundary markers: The instructions do not define explicit boundaries or warnings for the agent to distinguish between its instructions and the content within the documents it processes.
  • Capability inventory: The skill has the capability to read from and write to the file system (specifically in /tmp/docs and output/doc) and execute system commands for document processing.
  • Sanitization: The skill does not implement specific sanitization or filtering of the content or metadata within the documents before rendering or processing them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 08:50 AM