Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThe skill processes Office documents but contains vulnerabilities to XML External Entity (XXE) and Path Traversal (Zip Slip) attacks. It uses an insecure XML parser (lxml) and extracts ZIP files without validating filenames, which could allow a malicious document to read sensitive local files or overwrite system data.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · No issues
Runlayer
warn58/58 files flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed