document-docx
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/docx_quality_gate.pyusessubprocess.runto invokelibreofficeorsofficefor a conversion smoke test. The command is constructed using a structured list of arguments rather than a shell string, which mitigates the risk of command injection. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process and extract data from Word documents, which is a potential surface for indirect prompt injection.
- Ingestion points: Untrusted document content is ingested via
scripts/docx_extract.pyandscripts/docx_to_html.mjs. - Boundary markers: The documentation in
SKILL.mdandreferences/llm-extraction-workflows.mdwarns the agent to treat macro-enabled files as untrusted and provides explicit guidance on ignoring instructions inside documents. - Capability inventory: The skill has
BashandWritecapabilities, which could be misused if the agent obeys instructions found within a processed document. - Sanitization: The skill identifies that
mammoth.jsdoes not sanitize HTML output and explicitly instructs the user to sanitize it before use, even embedding a security warning into the generated HTML files. - [EXTERNAL_DOWNLOADS]: The skill references various libraries and documentation sources in
data/sources.json, including those from Microsoft, IBM (Docling), and Mistral AI. These are established technology vendors and their official resources are considered trusted.
Audit Metadata