docx

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes well-known, legitimate tools for document processing, including pandoc, LibreOffice, and Poppler.
  • [EXTERNAL_DOWNLOADS]: Recommends the installation of the 'docx' package from the official NPM registry for document generation.
  • [COMMAND_EXECUTION]: Instructions include the use of internal Python and JavaScript scripts for specialized tasks like document unpacking, XML validation, and tracked changes management.
  • [PROMPT_INJECTION]: The skill processes untrusted content from Word documents, which constitutes an indirect prompt injection surface.
  • Ingestion points: Text and metadata extraction via the Document tool and pandoc.
  • Boundary markers: None identified in the provided instructions.
  • Capability inventory: File system access (Read, Write, Edit, Glob, Grep) and execution of local scripts.
  • Sanitization: None explicitly mentioned for processing document content.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 04:17 AM
Security Audit — agent-trust-hub — docx