docuseal
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a standard productivity extension for the DocuSeal platform. All documented behaviors and commands are consistent with the intended purpose of managing digital signatures.\n- [COMMAND_EXECUTION]: The agent uses the
docusealCLI binary to perform document management tasks. This execution is limited to the functionality provided by the tool and does not involve arbitrary or dangerous command execution.\n- [EXTERNAL_DOWNLOADS]: The skill supports processing documents from remote URLs, which is a core feature of the DocuSeal service for handling cloud-hosted files. These references are documented neutrally and serve legitimate business use cases.\n- [PROMPT_INJECTION]: The skill defines an ingestion surface for PDF, DOCX, and HTML files containing field tags (e.g., infield-tags.mdandhtml-fields.md) and dynamic variables (indocx-variables.md). These documents are processed by the DocuSeal engine via the CLI (templates create-*,submissions create-*). While these tags influence the platform's behavior, they are a fundamental part of the service's templating system. Capability inventory includes sending signature request emails and template modification. Sanitization and parsing safety are managed by the DocuSeal platform side.
Audit Metadata