Back to skill

Security audit

Docx Builder

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Word document generator that creates local JavaScript and .docx files for the user-requested document task.

Before installing, expect it to install the docx npm package and create local .js and .docx outputs. Review generated filenames and paths, especially in shared or important directories, to avoid overwriting existing files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation rules are broad natural-language triggers such as requests to generate Word documents or structured documents, which can cause the skill to activate unexpectedly in contexts where the user did not explicitly intend to invoke it. In an agent system, overbroad activation can lead to unintended code generation and file-producing behavior, increasing the chance of surprising side effects or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to generate scripts and save output files locally, but it does not clearly require notifying the user before writing files. Hidden or implicit local file creation is dangerous because it can surprise users, overwrite existing files, or create artifacts in sensitive working directories without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file's natural-language content, including the title and document body strings, is entirely specified in Chinese and appears to define the generated document language by default. There is no indication that the user can choose another language or opt in to this locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

L022 将技能定位为生成任意形式 .docx 文档的专家,但全文默认采用中文说明体系,且 L060 明确固定字体为 Arial,未说明是否可根据用户语言或地区偏好调整。对面向广泛文档生成的技能而言,强制单一语言/排版本地化选择可能违反语言/locale 需经用户选择的要求。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The code saves output to './example-prd.docx', which is a file write operation. In this file there is no confirmation prompt, log/print statement, or comment/docstring disclosing that a file will be created at that path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.