docx
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill follows established best practices for document generation by separating content (Markdown) from presentation logic (Word reference templates). This architecture ensures that the rendering process is deterministic and consistent.
- [COMMAND_EXECUTION]: The skill uses a shell script
scripts/render.shto interface with the system'spandocandunziputilities. The script correctly quotes variables to prevent command injection and utilizes standard system tools for their intended purposes without escalating privileges. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied Markdown content, which creates a potential surface for indirect prompt injection. However, this risk is mitigated by the use of
pandoc, a robust and specialized parser that treats input as document structure rather than executable instructions. - Ingestion points: Markdown content files passed as the first argument to
scripts/render.sh. - Boundary markers: None explicitly implemented; the system relies on the structural constraints of the Markdown format and pandoc's parser.
- Capability inventory: Execution of
pandocandunzipwithin the local shell environment. - Sanitization: Shell arguments are properly quoted in
scripts/render.shto ensure data is treated as file paths and not as shell commands.
Audit Metadata