docx

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and manipulate external OOXML data from .docx files (e.g., in ooxml/scripts/unpack.py and scripts/document.py). It possesses exploitable capabilities including file system modification and system command execution.
  • Ingestion points: Raw XML files extracted from Word documents, specifically word/document.xml and word/comments.xml.
  • Boundary markers: The instructions do not define clear delimiters or specific warnings for the agent to ignore instructions that might be embedded within the document text.
  • Capability inventory: Includes system calls via subprocess.run to soffice and git, as well as directory manipulation using shutil.
  • Sanitization: The skill correctly employs the defusedxml library for all XML parsing, which effectively mitigates XML External Entity (XXE) vulnerabilities.
  • [COMMAND_EXECUTION]: The scripts ooxml/scripts/pack.py and ooxml/scripts/validation/redlining.py execute shell commands using subprocess.run.
  • pack.py invokes soffice (LibreOffice) for document validation by converting files to HTML.
  • redlining.py invokes git diff to perform character-level comparisons between document versions.
  • While these tools are used for legitimate functionality, they operate on file paths provided during execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — docx