redline-docx-pl
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent to use
uvxto download and execute theadeuutility from a remote package registry. This tool is the primary engine for the skill's document processing functionality. - [COMMAND_EXECUTION]: The skill executes local Python scripts (
memo_negocjacyjne.py,skan_placeholder.py) and theadeuCLI to perform document analysis, redlining, and sanitization. - [DATA_EXPOSURE]: The skill includes explicit instructions to use the
--authorflag when applying changes to documents to prevent the leakage of the local system's account name into document metadata. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect injection as it reads untrusted
.docxcontent. It mitigates this risk by defining a 'Safety Tier' framework that requires verbal or literal human confirmation ('potwierdzam') before performing mutating or destructive file operations.
Audit Metadata