skills/letta-ai/skills/doc/Gen Agent Trust Hub

doc

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/render_docx.py script executes system commands via subprocess.run to interact with soffice (LibreOffice) and pdftoppm. The implementation follows safety best practices by passing arguments as a list and not enabling shell execution (shell=True), which prevents typical command injection vulnerabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from external .docx files. This creates a surface for indirect prompt injection where maliciously crafted documents could contain instructions intended to override the agent's behavior. The workflow identifies this risk by suggesting visual review and calling out layout/text extraction risks.
  • [EXTERNAL_DOWNLOADS]: The skill instructions specify the installation of standard third-party libraries (python-docx, pdf2image) and system utilities (libreoffice, poppler-utils) from official repositories. These are standard dependencies required for the skill's stated purpose of document rendering and manipulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — doc