office-productivity

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface\n
  • Ingestion points: The workflow design involves importing data, connecting to data sources, and generating documents from data in Phases 2, 3, 5, and 7 of SKILL.md.\n
  • Boundary markers: The instructions do not define clear delimiters or include specific directives for the agent to disregard commands potentially embedded in the ingested data.\n
  • Capability inventory: The agent is instructed to invoke tools for document creation, spreadsheet automation, and presentation generation (such as libreoffice-writer, libreoffice-calc, docx-official, xlsx-official, etc.), which provides a path for data-driven file operations.\n
  • Sanitization: There are no provisions for sanitizing, validating, or escaping external content before it is processed or interpolated into document templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 07:46 AM
Security Audit — agent-trust-hub — office-productivity