skills/minimax-ai/skills/minimax-docx/Gen Agent Trust Hub

minimax-docx

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's setup and environment check scripts (scripts/setup.sh, scripts/env_check.sh, and scripts/setup.ps1) download the .NET SDK installation script from Microsoft's official dot.net domain. This is an expected operation for configuring the required runtime environment and originates from a trusted organization.
  • [REMOTE_CODE_EXECUTION]: Automated scans detected the download and execution of the .NET installation script. Per the skill's intended purpose and the trusted nature of the source (Microsoft), this behavior is categorized as safe and necessary for the tool's core document-processing functionality.
  • [COMMAND_EXECUTION]: The skill utilizes several standard CLI tools for its operations, including the .NET CLI (dotnet run) for document logic, pandoc for text-based document previews, and soffice (LibreOffice) for converting legacy .doc files into the modern .docx format.
  • [PRIVILEGE_ESCALATION]: The setup.sh script uses sudo commands with the system package manager (e.g., apt-get, dnf) to install the .NET SDK and other required utilities. This elevated access is limited to the initial installation of legitimate developer tools and system libraries.
  • [DYNAMIC_EXECUTION]: To handle complex structural document manipulations, the skill generates and executes C# scripts (scripts/dotnet/task.csx) using the .NET runner. This dynamic execution path is the primary mechanism for advanced document editing and is supported by a comprehensive library of verified code samples.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data sources such as JSON and CSV files to populate document content. This potential attack surface is mitigated by the skill's use of automated XSD schema validation (assets/xsd/) and explicit instructions for XML escaping of user-provided text, ensuring that ingested data does not compromise document integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:59 AM
Security Audit — agent-trust-hub — minimax-docx