document-processing-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to parse and process untrusted document formats (PDF, DOCX, XLSX, PPTX), which serve as a vector for indirect prompt injection and other document-based attacks.
- Ingestion points: Documents uploaded or provided by users are processed in
SKILL.mdandreferences/LIBRARIES.mdfor text extraction and manipulation. - Boundary markers: While no explicit prompt delimiters are provided for raw text extraction, the skill mandates
autoescape=Truewhen rendering document data via Jinja2 templates to prevent injection into the output document. - Capability inventory: The skill utilizes
Write,Edit, andBashtools (specifically forlibreofficeandqpdf) to handle file system operations and document conversions. - Sanitization: The skill provides a
safe_loadimplementation to enforce size and page limits and explicitly warns developers to treat documents as hostile input, highlighting risks like macros and XXE. - [COMMAND_EXECUTION]: The skill provides a implementation recipe that uses
subprocess.runto execute external binaries for document conversion. - Evidence: The
convertfunction inreferences/LIBRARIES.mdinvokeslibreofficeviasubprocess.runto perform headless document format conversion.
Audit Metadata