skills/jswortz/my-skills/docx/Gen Agent Trust Hub

docx

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes external binaries soffice and git through the subprocess.run function in ooxml/scripts/pack.py and ooxml/scripts/validation/redlining.py to perform document validation and version diffing. These calls are implemented as list-based arguments without shell invocation.
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection due to its document ingestion capabilities.
  • Ingestion points: Untrusted Office files are ingested and extracted in ooxml/scripts/unpack.py.
  • Boundary markers: Absent. The instructions do not define delimiters or provide specific guidance to help the agent distinguish between its system instructions and content found within processed documents.
  • Capability inventory: The skill uses subprocess.run to execute external utilities in ooxml/scripts/pack.py and ooxml/scripts/validation/redlining.py.
  • Sanitization: Present for XML processing. The skill consistently uses defusedxml in scripts/document.py, ooxml/scripts/pack.py, and ooxml/scripts/unpack.py to protect against XML External Entity (XXE) vulnerabilities. However, zipfile.extractall is used in ooxml/scripts/unpack.py without explicit validation of extraction paths, which is a potential risk when handling malicious archives.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 02:09 PM
Security Audit — agent-trust-hub — docx