document-docx

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/docx_quality_gate.py uses subprocess.run to invoke libreoffice or soffice for a conversion smoke test. The command is constructed using a structured list of arguments rather than a shell string, which mitigates the risk of command injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process and extract data from Word documents, which is a potential surface for indirect prompt injection.
  • Ingestion points: Untrusted document content is ingested via scripts/docx_extract.py and scripts/docx_to_html.mjs.
  • Boundary markers: The documentation in SKILL.md and references/llm-extraction-workflows.md warns the agent to treat macro-enabled files as untrusted and provides explicit guidance on ignoring instructions inside documents.
  • Capability inventory: The skill has Bash and Write capabilities, which could be misused if the agent obeys instructions found within a processed document.
  • Sanitization: The skill identifies that mammoth.js does not sanitize HTML output and explicitly instructs the user to sanitize it before use, even embedding a security warning into the generated HTML files.
  • [EXTERNAL_DOWNLOADS]: The skill references various libraries and documentation sources in data/sources.json, including those from Microsoft, IBM (Docling), and Mistral AI. These are established technology vendors and their official resources are considered trusted.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — document-docx