docx
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and manipulate external OOXML data from
.docxfiles (e.g., inooxml/scripts/unpack.pyandscripts/document.py). It possesses exploitable capabilities including file system modification and system command execution. - Ingestion points: Raw XML files extracted from Word documents, specifically
word/document.xmlandword/comments.xml. - Boundary markers: The instructions do not define clear delimiters or specific warnings for the agent to ignore instructions that might be embedded within the document text.
- Capability inventory: Includes system calls via
subprocess.runtosofficeandgit, as well as directory manipulation usingshutil. - Sanitization: The skill correctly employs the
defusedxmllibrary for all XML parsing, which effectively mitigates XML External Entity (XXE) vulnerabilities. - [COMMAND_EXECUTION]: The scripts
ooxml/scripts/pack.pyandooxml/scripts/validation/redlining.pyexecute shell commands usingsubprocess.run. pack.pyinvokessoffice(LibreOffice) for document validation by converting files to HTML.redlining.pyinvokesgit diffto perform character-level comparisons between document versions.- While these tools are used for legitimate functionality, they operate on file paths provided during execution.
Audit Metadata