Back to skill

Security audit

BookOrigin DOCX Review

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local-only DOCX preflight and advisory review-package tool with no hidden network, persistence, or document-writing behavior found.

Install only if you need a local DOCX structure preflight and advisory review manifest tool. It reads the DOCX and JSON files you point it at and outputs hashes and limited findings, but it is not a malware scanner, legal approval system, signature tool, or document-quality verifier.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
selfcheck.mjs:18