docx
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted Word documents, creating a potential surface for indirect prompt injection where malicious content in a document could influence the AI agent's behavior. Ingestion points for document data include pandoc for text extraction and raw XML parsing in ooxml/scripts/unpack.py, with no boundary markers or sanitization to distinguish document content from agent instructions.
- [DYNAMIC_EXECUTION]: The ooxml/scripts/unpack.py script uses zipfile.ZipFile.extractall() for unpacking documents, which can be vulnerable to path traversal (Zip Slip) if the document is maliciously crafted to include filenames with directory traversal sequences.
- [COMMAND_EXECUTION]: The skill uses system tools like soffice (LibreOffice), git, and pandoc to perform document tasks. These are executed via subprocess.run with argument lists, which is a safe practice to prevent shell injection.
Audit Metadata