Back to skill

Security audit

国央企word文档

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Chinese government/SOE Word document generator that only creates local DOCX files, though its dependency hygiene should be reviewed.

Install this only if you want China-specific government or central SOE Word document formatting. Keep generated output paths under user control to avoid overwriting files, and update or audit the docx/nanoid dependency tree before using it for sensitive document workflows.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
node scripts/create_gov_doc.js output.docx '{

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 376)May include surrounding context.

md
node scripts/create_gov_doc.js output.docx '{

Known Vulnerable Dependency: nanoid==5.1.7 — 2 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-73086 (nanoid: Integer Overflow or Wraparound)

High
Category
Supply Chain
Confidence
93% confidence
Finding

The lockfile pins nanoid to 5.1.7, which is reported as affected by advisories involving negative-size infinite looping in non-secure generators and integer overflow/wraparound. Even though this package is only a transitive dependency of docx and may not be directly invoked by the skill, shipping a known vulnerable version is still a real supply-chain risk if the affected code path is reachable during document generation or any helper tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description states the skill is for creating documents that conform to Chinese government and central SOE standards whenever users request certain formal documents. This imposes a specific locale/governance format by default and does not indicate user opt-in or clarify that the constraint is limited to users who explicitly want that regional format.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The package description states the skill creates documents that conform to Chinese government and state-owned enterprise standards, expressed only in Chinese. This indicates a fixed language/locale context without any mention of user choice or opt-in, which matches the policy concern for language or locale constraints stated in natural language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file description states it creates documents compliant with Chinese government document standards, and the implementation consistently hard-codes Chinese fonts, Chinese numbering, and Chinese labels. This imposes a specific locale/language behavior with no opt-in or alternative, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file uses natural-language positioning that constrains the skill to a specific Chinese governmental/enterprise document context and Chinese formatting conventions. Because the file does not present this as a user-selectable locale option, it can be read as enforcing a specific language/locale by default.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

Using a caret version range for the docx dependency allows automatic installation of newer compatible releases, which can unexpectedly introduce vulnerable or malicious code through the supply chain. In a document-generation skill, compromised dependencies could affect generated files, exfiltrate document contents, or execute unwanted logic during processing.

Content

Scanner excerpt · package.json (reported line 7)May include surrounding context.

json
"description": "创建符合中国政府及央企规范的Word文档(.docx)",
  "author": "刘洪亮",
  "dependencies": {
    "docx": "^9.6.1"
  }
}

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+2 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
node_modules/@types/node/child_process.d.ts:122

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
node_modules/@types/node/repl.d.ts:40

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
node_modules/@types/node/vm.d.ts:542

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
node_modules/docx/dist/index.cjs:21152

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
node_modules/docx/dist/index.iife.js:21152

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
node_modules/docx/dist/index.mjs:21150

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
node_modules/docx/dist/index.umd.cjs:21154

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
node_modules/jszip/dist/jszip.js:11404

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
node_modules/jszip/dist/jszip.min.js:13

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
node_modules/setimmediate/setImmediate.js:17

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
node_modules/xml-js/dist/xml-js.js:7928

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
node_modules/xml-js/dist/xml-js.min.js:8

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
node_modules/@types/node/http.d.ts:1390

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
node_modules/@types/node/crypto.d.ts:539

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
node_modules/jszip/dist/jszip.js:1297

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
node_modules/jszip/lib/utils.js:382