docx

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements secure document processing workflows. XML manipulation is primarily handled using the defusedxml library to protect against XML External Entity (XXE) and other XML-based attacks. Subprocess calls for document validation and diffing in ooxml/scripts/pack.py and ooxml/scripts/validation/redlining.py use argument lists, preventing shell command injection. The ingestion of untrusted document content (Category 8 surface) is a core part of the skill's purpose and is handled defensively. No evidence of prompt injection, data exfiltration, or obfuscation was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 11:33 AM
Security Audit — agent-trust-hub — docx