minimax-docx
Fail
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The setup utilities in scripts/setup.sh and scripts/env_check.sh download and execute an installation script from https://dot.net/v1/dotnet-install.sh. Although this source is a well-known Microsoft domain, the execution of downloaded remote scripts is a monitored security behavior.
- [PRIVILEGE_ESCALATION]: The installation script scripts/setup.sh utilizes sudo to install necessary system packages like pandoc and libreoffice-core via standard package managers during the initial environment configuration.
- [PERSISTENCE_MECHANISMS]: During the setup process, the scripts/setup.sh script appends configuration to the user's ~/.bashrc file to ensure the .dotnet binaries are available in the system PATH for future shell sessions.
- [METADATA_POISONING]: The SKILL.md file identifies the author as MiniMaxAI, whereas the skill is attributed to hk-hub in the platform context. This discrepancy in identity can be used to mislead users regarding the skill's origin and safety.
- [INDIRECT_PROMPT_INJECTION]: The document generation and editing logic in EditContentCommand.cs and CreateCommand.cs ingests untrusted text and structured data from JSON and CSV files without explicit sanitization or boundary delimiters, which represents an indirect prompt injection surface.
Recommendations
- HIGH: Downloads and executes remote code from: https://dot.net/v1/dotnet-install.sh - DO NOT USE without thorough review
Audit Metadata