docx
Warn
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The script scripts/office/soffice.py performs runtime compilation of C source code and uses library injection. Evidence includes the use of gcc to compile a shared object from an embedded string and the subsequent setting of the LD_PRELOAD environment variable to the path of the compiled object.
- [COMMAND_EXECUTION]: Multiple scripts execute system-level commands via the subprocess module to perform document conversion, validation, and comparisons. Examples include calling gcc in scripts/office/soffice.py, soffice in scripts/accept_changes.py, and git diff in scripts/office/validators/redlining.py.
- [PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection by processing untrusted document content without explicit boundary markers. 1. Ingestion points: document.xml content processed in scripts/office/validators/redlining.py. 2. Boundary markers: Absent. 3. Capability inventory: Execution of system commands and C compilation. 4. Sanitization: Partial, using defusedxml for some XML parsing and a safe extraction helper for archives.
Audit Metadata