Tp2
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed Chinese government/SOE Word document generator that only creates local DOCX files, though its dependency hygiene should be reviewed.
Install this only if you want China-specific government or central SOE Word document formatting. Keep generated output paths under user control to avoid overwriting files, and update or audit the docx/nanoid dependency tree before using it for sensitive document workflows.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Referenced artifact was not completely inspected
node scripts/create_gov_doc.js output.docx '{
Referenced artifact was not completely inspected
node scripts/create_gov_doc.js output.docx '{
The lockfile pins nanoid to 5.1.7, which is reported as affected by advisories involving negative-size infinite looping in non-secure generators and integer overflow/wraparound. Even though this package is only a transitive dependency of docx and may not be directly invoked by the skill, shipping a known vulnerable version is still a real supply-chain risk if the affected code path is reachable during document generation or any helper tooling.
The description states the skill is for creating documents that conform to Chinese government and central SOE standards whenever users request certain formal documents. This imposes a specific locale/governance format by default and does not indicate user opt-in or clarify that the constraint is limited to users who explicitly want that regional format.
The package description states the skill creates documents that conform to Chinese government and state-owned enterprise standards, expressed only in Chinese. This indicates a fixed language/locale context without any mention of user choice or opt-in, which matches the policy concern for language or locale constraints stated in natural language.
The file description states it creates documents compliant with Chinese government document standards, and the implementation consistently hard-codes Chinese fonts, Chinese numbering, and Chinese labels. This imposes a specific locale/language behavior with no opt-in or alternative, which matches the language/locale policy violation criteria.
This markdown file uses natural-language positioning that constrains the skill to a specific Chinese governmental/enterprise document context and Chinese formatting conventions. Because the file does not present this as a user-selectable locale option, it can be read as enforcing a specific language/locale by default.
Using a caret version range for the docx dependency allows automatic installation of newer compatible releases, which can unexpectedly introduce vulnerable or malicious code through the supply chain. In a document-generation skill, compromised dependencies could affect generated files, exfiltrate document contents, or execute unwanted logic during processing.
"description": "创建符合中国政府及央企规范的Word文档(.docx)",
"author": "刘洪亮",
"dependencies": {
"docx": "^9.6.1"
}
}
Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+2 more)