Back to skill

Security audit

Gongwen Formatter 公文格式转换

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Markdown-to-Word formatter with expected file output and optional remote image fetching, but users should disable image downloads for untrusted documents or restricted networks.

Install only if you need Chinese GB/T 9704-2012 Word formatting. For Markdown from untrusted sources or use inside intranet, classified, or otherwise sensitive networks, call md_to_docx with download_images=False so embedded image URLs are not fetched automatically.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'file_read' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The module performs outbound network access by downloading remote images from user-supplied Markdown URLs, but the skill metadata does not declare network capability/permission. Even though the code restricts schemes to http/https/data:image, this still enables server-side requests to arbitrary external hosts and can be abused for SSRF to internal services, metadata endpoints, or network scanning if the runtime has sensitive network reachability. The skill context increases risk because remote image download is an optional feature exposed directly to untrusted input.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The top-level docstring states the skill is specifically for converting Markdown into Chinese party/government document format under GB/T 9704-2012. This is a locale-specific constraint presented as the module's fixed behavior, with no indication elsewhere in the file that users can opt into another language or locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This markdown file contains natural-language product policy information. The phrase '便于中文用户在 SkillHub 检索' describes a deliberate language-targeted naming decision, but the file does not indicate any user choice or explicitly justified regional constraint. That can be read as a locale/language policy issue under the rule for forced language behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The README is labeled as English and describes conversion to 'Chinese government official document format,' which implies a fixed locale-specific output behavior. The document does not clearly frame this as a user-selected locale option or region-scoped mode, so it can be read as imposing a specific locale by default.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: python-docx has 2 known advisory(ies) (CVE-2016-5851 (Improper Restriction of XML External Entity Reference in python-docx); CVE-2016-5851 (python-docx before 0.8.6 allows context-dependent attackers to conduct XML Exter)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency is only loosely pinned with ~=1.1.0, so the exact installed build is not fully deterministic and the manifest does not demonstrate whether all security-fixed releases are enforced across environments. Because python-docx has a history of XXE-related issues, uncertainty around dependency versioning can expose document-processing code to parser-related attacks if a vulnerable transitive or selected version is resolved.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: markdown-it-py has 4 known advisory(ies) (CVE-2023-26302 (markdown-it-py Denial of Service vulnerability in the command line interface); CVE-2023-26303 (markdown-it-py Denial of Service vulnerability); CVE-2023-26302 (Denial of service could be caused to the command line interface of markdown-it-p) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The package is specified with a compatible range rather than an exact locked version, so different environments may resolve different releases and the manifest does not prove that vulnerable versions are excluded. Since markdown-it-py has had denial-of-service issues, this creates avoidable risk in a skill that converts attacker-controlled Markdown input and could be driven into excessive resource consumption if an affected version is installed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The package description is written only in Chinese ('公文格式转换 - 将 Markdown 转为党政机关公文格式'), which can amount to a language/locale constraint in the skill's natural-language metadata. The file does not indicate that users can choose another language or that the locale restriction is explicitly documented as an opt-in policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The module docstring states that the skill converts Markdown into Word documents conforming to a Chinese government document standard. This is a locale-specific behavior presented as the default purpose of the skill, but the file does not indicate any user choice or opt-in regarding language or locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.