skills/mrgoonie/claudekit-skills/docx/Gen Agent Trust Hub

docx

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from potentially untrusted Word documents. Malicious documents could contain instructions designed to influence the agent's behavior during content analysis.
  • Ingestion points: Content is imported into the context via ooxml/scripts/unpack.py and pandoc extraction commands described in SKILL.md.
  • Boundary markers: There are no explicit instructions for the agent to use delimiters or ignore embedded instructions within processed document text.
  • Capability inventory: The skill can execute shell commands (soffice, git, pandoc) and perform file system writes via scripts/document.py and ooxml/scripts/pack.py.
  • Sanitization: The implementation consistently uses the defusedxml library, which effectively mitigates XML External Entity (XXE) and other XML-based injection vulnerabilities.
  • [COMMAND_EXECUTION]: The skill executes system commands to perform document validation and comparison tasks. ooxml/scripts/pack.py uses subprocess.run to call soffice for converting and validating Office files, and ooxml/scripts/validation/redlining.py uses it to call git diff for comparing document revisions. These operations are limited to the skill's primary document manipulation functions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:16 AM
Security Audit — agent-trust-hub — docx