Back to skill

Security audit

Office Automation Toolkit

Security checks for vulnerabilities and agentic risk

Overview

This office automation toolkit is mostly a real tool catalog, but it also includes broad automatic setup and credential-binding behavior that users should review before installing.

Review this skill before installing or running its bootstrap script. Prefer --check-only first, avoid running it with elevated privileges unless necessary, verify the package list, and be aware that it may install software, download browser assets, and bind messaging credentials when matching environment variables exist.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/toolkit-bootstrap.sh:132
Finding

Unpinned Third-Party Python Package Installation

Content
View full analysis
/dev/null || pip install --quiet "$pkg" 2>/dev/null else pip3 install "$pkg" 2>/dev/null || pip install "$pkg" 2>/dev/null fi } ``` The script also downloads an unpinned Playwright browser artifact: ```bash if check_python_module "playwright" && ! python3 -c "from playwright.sync_api import sync_playwright; p=sync_playwright().start(); p.chromium" 2>/dev/null; then warn "Playwright is installed but the Chromium browser is unavailable" if [[ "$CHECK_ONLY" == false ]]; then info "Downloading Chromium..." playwright install chromium 2>/dev/null || warn "Chromium download failed; run manually: playwright install chromium" fi fi ``` ### Technical Analysis The bootstrap script installs packages by name from the Python package index without specifying reviewed versions, cryptographic hashes, a lockfile, or an explicitly trusted index. The package names originate from the fixed `TOOLS` array, so direct command injection through `pkg` was not identified. However, commands such as `pip3 install "$pkg"` resolve mutable package releases and their transitive dependencies at installation time. Consequently, the code executed or installed by the bootstrap can differ from the code reviewed during this audit. If a referenced package, one of its dependencies, its maintainer account, or the configured package index is compromised, a malicious release can be selected. Python installation mechanisms may execute build backends or other pac ...[truncated 2515 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The stated purpose is a passive registry of office automation tools, but the content includes actionable installation and credential-binding operations such as pip installs, system package installs, browser binary download, and lark-cli credential binding. This mismatch is dangerous because an agent or user may treat the skill as informational while it implicitly authorizes environment modification, external downloads, and use of preprovisioned credentials.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file is presented as a zero-configuration tool registry/list, but it actually performs package installation, downloads binaries, invokes sudo-backed system changes, and binds external platform tooling. That mismatch increases the chance a user or calling agent will treat it as informational metadata and trigger unintended system modification and credential-scoped actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script inspects communication-platform credentials from environment variables and automatically binds lark-cli when Feishu credentials are present. In the context of a tool catalog skill, touching live credentials and changing client configuration is unexpected and can cause unauthorized account linkage, credential misuse, or cross-tenant actions if invoked by an automated agent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises or enables capabilities involving shell/package installation and network access, but it does not declare any explicit tool scope such as allowed-tools or permissions. That creates an authorization gap: downstream agents may invoke powerful tools beyond what a user would reasonably expect from a 'tool registry' document, increasing the risk of unintended command execution or outbound access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are generic terms like 'toolkit' and '有哪些工具', which can be matched during ordinary conversation unrelated to this specific skill. Overbroad activation increases the chance that the skill is invoked unexpectedly, potentially exposing package-install, network, or credential-backed recommendations in contexts where the user did not intend to enable them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill lists networked, browser-automation, and credential-backed tools including Playwright, requests/httpx, lark-cli, and preprovisioned credential binding, but provides no user-facing warnings about data egress, stored authentication state, or the use of organizational credentials. In this context, the omission is risky because the skill is positioned as 'zero-config' and may normalize powerful operations without informing users of privacy, authentication, or side-effect implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script claims a '--yes' flag skips confirmation, but there is no actual confirmation prompt in either mode; package installation proceeds automatically whenever the script is not run with '--check-only'. This creates deceptive UX and can lead users or orchestrators to trigger unreviewed system changes and privilege-escalated installs unintentionally.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/toolkit-bootstrap.sh (reported line 146)May include surrounding context.

sh
local pkg="$1"
  info "apt install $pkg"
  if [[ "$AUTO_YES" == true ]]; then
    sudo apt-get install -y -qq "$pkg" 2>/dev/null
  else
    sudo apt-get install -y "$pkg" 2>/dev/null
  fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/toolkit-bootstrap.sh (reported line 148)May include surrounding context.

sh
local pkg="$1"
  info "apt install $pkg"
  if [[ "$AUTO_YES" == true ]]; then
    sudo apt-get install -y -qq "$pkg" 2>/dev/null
  else
    sudo apt-get install -y "$pkg" 2>/dev/null
  fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/toolkit-bootstrap.sh (reported line 156)May include surrounding context.

sh
local pkg="$1"
  info "apt install $pkg"
  if [[ "$AUTO_YES" == true ]]; then
    sudo apt-get install -y -qq "$pkg" 2>/dev/null
  else
    sudo apt-get install -y "$pkg" 2>/dev/null
  fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/toolkit-bootstrap.sh (reported line 158)May include surrounding context.

sh
local pkg="$1"
  info "apt install $pkg"
  if [[ "$AUTO_YES" == true ]]; then
    sudo apt-get install -y -qq "$pkg" 2>/dev/null
  else
    sudo apt-get install -y "$pkg" 2>/dev/null
  fi

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script prints sensitive environment variable values such as FEISHU_APP_ID and WECOM_CORP_ID directly to console output. Console logs are often persisted or visible to other systems, so exposing credential-related identifiers can leak tenant metadata and aid follow-on targeting or unauthorized integration attempts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Natural-language strings in the header and usage instructions force a specific language/locale for users regardless of preference. The policy requires avoiding language constraints unless users are given a choice or the locale limitation is clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script automatically downloads Playwright Chromium binaries once it detects the Python package but missing browser assets, without a separate user confirmation. While common in setup flows, it still causes unannounced network activity and filesystem changes that are riskier in an agent-executed or supposedly catalog-only skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.