Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'file_read' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed Markdown-to-Word formatter with expected file output and optional remote image fetching, but users should disable image downloads for untrusted documents or restricted networks.
Install only if you need Chinese GB/T 9704-2012 Word formatting. For Markdown from untrusted sources or use inside intranet, classified, or otherwise sensitive networks, call md_to_docx with download_images=False so embedded image URLs are not fetched automatically.
The skill uses 'file_read' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The module performs outbound network access by downloading remote images from user-supplied Markdown URLs, but the skill metadata does not declare network capability/permission. Even though the code restricts schemes to http/https/data:image, this still enables server-side requests to arbitrary external hosts and can be abused for SSRF to internal services, metadata endpoints, or network scanning if the runtime has sensitive network reachability. The skill context increases risk because remote image download is an optional feature exposed directly to untrusted input.
The top-level docstring states the skill is specifically for converting Markdown into Chinese party/government document format under GB/T 9704-2012. This is a locale-specific constraint presented as the module's fixed behavior, with no indication elsewhere in the file that users can opt into another language or locale.
This markdown file contains natural-language product policy information. The phrase '便于中文用户在 SkillHub 检索' describes a deliberate language-targeted naming decision, but the file does not indicate any user choice or explicitly justified regional constraint. That can be read as a locale/language policy issue under the rule for forced language behavior.
The README is labeled as English and describes conversion to 'Chinese government official document format,' which implies a fixed locale-specific output behavior. The document does not clearly frame this as a user-selected locale option or region-scoped mode, so it can be read as imposing a specific locale by default.
The dependency is only loosely pinned with ~=1.1.0, so the exact installed build is not fully deterministic and the manifest does not demonstrate whether all security-fixed releases are enforced across environments. Because python-docx has a history of XXE-related issues, uncertainty around dependency versioning can expose document-processing code to parser-related attacks if a vulnerable transitive or selected version is resolved.
The package is specified with a compatible range rather than an exact locked version, so different environments may resolve different releases and the manifest does not prove that vulnerable versions are excluded. Since markdown-it-py has had denial-of-service issues, this creates avoidable risk in a skill that converts attacker-controlled Markdown input and could be driven into excessive resource consumption if an affected version is installed.
The package description is written only in Chinese ('公文格式转换 - 将 Markdown 转为党政机关公文格式'), which can amount to a language/locale constraint in the skill's natural-language metadata. The file does not indicate that users can choose another language or that the locale restriction is explicitly documented as an opt-in policy.
The module docstring states that the skill converts Markdown into Word documents conforming to a Chinese government document standard. This is a locale-specific behavior presented as the default purpose of the skill, but the file does not indicate any user choice or opt-in regarding language or locale.
No suspicious patterns detected.