Back to skill

Security audit

Office Pro

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Office document generator, but its file output handling can overwrite arbitrary writable paths if an agent passes unsafe filenames.

Review this skill before installing. Use it only with trusted prompts and trusted output filenames, avoid absolute paths or ../ path components, and do not let untrusted users control spreadsheet cell values. Generated contracts, rosters, invoices, and reports may contain sensitive business or personal data, so store and share the files carefully.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
simple_api.py:214
Finding

Caller-Controlled Output Path Allows Arbitrary File Overwrite

Content
View full analysis
Remediation
View remediation
Path: base = output_dir.resolve() supplied = Path(filename) if supplied.is_absolute() or supplied.name != filename: raise ValueError("Output must be a plain filename") if supplied.suffix.lower() != extension: raise ValueError(f"Output filename must end with {extension}") candidate = (base / supplied.name).resolve() if candidate.parent != base: raise ValueError("Output path escapes the configured output directory") if candidate.exists(): raise FileExistsError(f"Output file already exists: {candidate}") return candidate ``` Use this helper before every save operation: ```python output_path = _safe_output_path( self.output_dir, output_filename, ".xlsx", ) wb.save(str(output_path)) ``` If nested output directories are an intended feature, use `candidate.relative_to(base)` after resolution instead of requiring `candidate.parent == base`, and reject the path when `relative_to()` raises `ValueError`. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
simple_api.py:286
Finding

Untrusted Cell Values Are Written as Executable Spreadsheet Formulas

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broader document automation suite covering Word contracts, Excel reports, and report templates. The supplied code implements only a static library of 10 built-in contract templates, which does align with the '10 contract templates' portion and 'no external template files required' idea. However, the main claimed capabilities—document generation, Excel/report support, and unified automation—are not present in this chunk. Therefore the description materially overstates what this code actually does.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language instructions, headings, examples, and template labels are presented only in Chinese, which effectively forces a specific language for users. Under SQP-3, a language or locale policy violation exists when a skill imposes a language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing title, feature descriptions, template names, and examples are predominantly in Chinese, while the file does not state that the skill is China-specific or offer an alternate language option. This can constitute a language/locale policy issue because the skill's natural-language interface appears fixed to a single language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is designed to generate contracts, reports, and spreadsheets that may contain names, employment data, financial details, or business records, yet the documentation does not warn users about handling sensitive output files. This increases the chance that agents or users will save regulated or confidential data to insecure locations, share files broadly, or retain them longer than intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code converts numbers to Chinese characters and the generated documents use Chinese labels and date formats throughout, indicating the skill forces a specific language/locale. The file does not provide any opt-in, configuration, or documented justification for restricting output to Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The generated contract uses Chinese date formatting and Chinese field labels such as '合同编号' and '签署日期', and similar Chinese-only labels recur elsewhere in the file. Because the skill presents this as a general 'Quick document generator for AI Agents' rather than a region-specific tool, this is a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file hard-codes spreadsheet titles, descriptions, column names, and validation values in Chinese across all templates. Because the file provides no opt-in, locale selection, or justification that the skill is China-specific, it creates a natural-language locale policy issue by forcing a specific language on users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template titles, section headers, and default content are written entirely in Chinese, which enforces a specific language in generated reports. Under the policy, this is a natural-language locale constraint that should either offer user opt-in/choice or be explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file demonstrates generating contracts, employee rosters, financial reports, invoices, and meeting reports using names, company data, and other potentially sensitive content, but it does not warn users that the skill will create local files containing sensitive information. For markdown files, SQP-2 applies when the description omits warnings about behaviors that could affect user data, privacy, or system integrity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The quick-start example uses Chinese party names and location text, and the feature set includes num_to_chinese, which suggests a Chinese-language/locale bias in the skill's presentation. Because the file does not indicate that the tool is region-specific or that users can choose another language/locale, this may conflict with the policy against forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency is specified with a lower bound only, which allows different versions to be installed over time and makes builds non-reproducible. In a document-processing skill, this increases supply-chain risk and makes it harder to verify whether a safe version of python-docx is actually used, especially given historical XXE issues in older releases.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
python-docx>=1.1.2
openpyxl>=3.1.5

Unverifiable Dependency: python-docx has 2 known advisory(ies) (CVE-2016-5851 (Improper Restriction of XML External Entity Reference in python-docx); CVE-2016-5851 (python-docx before 0.8.6 allows context-dependent attackers to conduct XML Exter)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

python-docx has historical advisories involving XML external entity handling, and the unpinned requirement prevents verification that deployment avoids affected releases. In a document automation skill, document parsers are security-sensitive, so uncertainty around the exact installed version is a meaningful risk even if the minimum version may be newer than the cited vulnerable range.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

Using an unpinned openpyxl dependency permits installation of any newer matching version, reducing reproducibility and weakening assurance about the exact code running in production. Because this skill handles Office documents, dependency drift can expose the agent to parser-related vulnerabilities or unexpected behavior changes.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
python-docx>=1.1.2
openpyxl>=3.1.5

Unverifiable Dependency: openpyxl has 2 known advisory(ies) (CVE-2017-5992 (Improper Restriction of XML External Entity Reference in Openpyxl); CVE-2017-5992 (Openpyxl 2.4.1 resolves external entities by default, which allows remote attack)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

openpyxl has had XXE-related advisories, and because the requirement is not pinned, the manifest does not prove that only a safe release will be installed. This matters more in an Office automation context because spreadsheet libraries often parse complex XML-based formats and can become attack surfaces when handling untrusted files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This Python file contains natural-language content that fixes both locale and language to Chinese legal usage. Under the policy rule, forcing a specific language without user opt-in can be a locale/language policy issue unless clearly presented as a justified region-specific constraint to users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.