Office Docs

Security checks across malware telemetry and agentic risk

Overview

This Office document helper is coherent and low-risk, though users should be careful because it can guide agents to read, write, convert, and batch-process local documents.

Install only if you want Codex to help with local Office documents. Give explicit input and output paths, confirm before edits, conversions, or batch jobs, and keep backups of important or sensitive documents. Install optional external document tools only from trusted sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is extremely broad ('any other Office document tasks') and encourages invocation for a wide range of document-related operations without clear scoping or safety boundaries. Overly broad routing can cause the agent to select this skill for untrusted document handling, conversions, or scripted processing in situations where stricter validation and narrower permissions would be more appropriate.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal