docx
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from potentially untrusted Word documents. Malicious documents could contain instructions designed to influence the agent's behavior during content analysis.
- Ingestion points: Content is imported into the context via
ooxml/scripts/unpack.pyandpandocextraction commands described inSKILL.md. - Boundary markers: There are no explicit instructions for the agent to use delimiters or ignore embedded instructions within processed document text.
- Capability inventory: The skill can execute shell commands (
soffice,git,pandoc) and perform file system writes viascripts/document.pyandooxml/scripts/pack.py. - Sanitization: The implementation consistently uses the
defusedxmllibrary, which effectively mitigates XML External Entity (XXE) and other XML-based injection vulnerabilities. - [COMMAND_EXECUTION]: The skill executes system commands to perform document validation and comparison tasks.
ooxml/scripts/pack.pyusessubprocess.runto callsofficefor converting and validating Office files, andooxml/scripts/validation/redlining.pyuses it to callgit difffor comparing document revisions. These operations are limited to the skill's primary document manipulation functions.
Audit Metadata