Back to skill

Security audit

persian-documents

Security checks for vulnerabilities and agentic risk

Overview

The skill is a local Persian document generation and validation aid, and I found no hidden network, credential, persistence, or privilege behavior.

Install this if you want a local helper for Persian RTL DOCX/PDF generation and validation. Treat document configs as normal local input files, review generated documents for quality, and do not expect it to safely repair arbitrary existing documents automatically.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
83% confidence
Finding

The description broadly claims a skill for producing Persian documents across multiple document types, including PDFs and Word documents, and for fixing RTL/direction issues in Persian documents generally. The supplied code chunk is much narrower: it is a PDF generator script with HTML/CSS-based RTL formatting and a limited fallback path. It does support core declared behavior around Persian RTL layout, mixed Persian/Latin handling, code/URLs, and professional-ish PDF generation. However, there are material gaps: there is no Word/DOCX generation, no mechanism for editing or repairing existing documents, and no generalized document regeneration beyond creating output from JSON config or a built-in sample. Also, the ReportLab fallback does not preserve most rich content features, so the implementation is less comprehensive than the description suggests. Therefore this is a partial but meaningful description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a clear purpose mismatch. The declared description says the skill should create or regenerate production-quality Persian documents and fix RTL/direction problems in final output. The supplied code only validates existing text/documents for suspected RTL issues such as reversed English, malformed URLs, glyph choices, mixed-direction text, and some DOCX/PDF structural hints. It operates as an auditing/checking tool, not a document authoring or repair tool. While validation could be supportive to a document-production workflow, it is not the primary behavior described. No concerning undeclared external access appears beyond reading local files, but the main function is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: persian-documents
description: Generate production-quality Persian documents with correct RTL layout, bidirectional text handling, and professional typography. Use this skill whenever the user asks to create Persian documents — reports, letters, articles, technical documentation, resumes, PDFs, Word documents, or any document containing Persian text mixed with English, numbers, code, URLs, or other LTR content. Also trigger when the user asks to "fix RTL" or "fix direction" in a Persian document, or when a document needs to be regenerated because Persian text rendered incorrectly. This skill is NOT just for w

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
ZWNJ (U+200C) is used to prevent two characters from joining. Meaningful uses in Persian:

- **Verb prefixes**: می‌خواهم (I want), می‌شود (becomes), می‌توانم (I can)
- **Compound words**: کتاب‌ها (books), خانه‌ها (houses)
- **After certain particles**: از او، با او، در او
- **Before certain suffixes**: نمی‌روم، نمی‌خوانم

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
ZWNJ (U+200C) is used to prevent two characters from joining. Meaningful uses in Persian:

- **Verb prefixes**: می‌خواهم (I want), می‌شود (becomes), می‌توانم (I can)
- **Compound words**: کتاب‌ها (books), خانه‌ها (houses)
- **After certain particles**: از او، با او، در او
- **Before certain suffixes**: نمی‌روم، نمی‌خوانم

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · agents/grader.md (reported line 79)May include surrounding context.

md
ZWNJ (U+200C) is used to prevent two characters from joining. Meaningful uses in Persian:

- **Verb prefixes**: می‌خواهم (I want), می‌شود (becomes), می‌توانم (I can)
- **Compound words**: کتاب‌ها (books), خانه‌ها (houses)
- **After certain particles**: از او، با او، در او
- **Before certain suffixes**: نمی‌روم، نمی‌خوانم

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/document-patterns.md (reported line 141)May include surrounding context.

md
ZWNJ (U+200C) is used to prevent two characters from joining. Meaningful uses in Persian:

- **Verb prefixes**: می‌خواهم (I want), می‌شود (becomes), می‌توانم (I can)
- **Compound words**: کتاب‌ها (books), خانه‌ها (houses)
- **After certain particles**: از او، با او، در او
- **Before certain suffixes**: نمی‌روم، نمی‌خوانم

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/document-patterns.md (reported line 166)May include surrounding context.

md
ZWNJ (U+200C) is used to prevent two characters from joining. Meaningful uses in Persian:

- **Verb prefixes**: می‌خواهم (I want), می‌شود (becomes), می‌توانم (I can)
- **Compound words**: کتاب‌ها (books), خانه‌ها (houses)
- **After certain particles**: از او، با او، در او
- **Before certain suffixes**: نمی‌روم، نمی‌خوانم

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/document-patterns.md (reported line 176)May include surrounding context.

md
ZWNJ (U+200C) is used to prevent two characters from joining. Meaningful uses in Persian:

- **Verb prefixes**: می‌خواهم (I want), می‌شود (becomes), می‌توانم (I can)
- **Compound words**: کتاب‌ها (books), خانه‌ها (houses)
- **After certain particles**: از او، با او، در او
- **Before certain suffixes**: نمی‌روم، نمی‌خوانم

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/document-patterns.md (reported line 177)May include surrounding context.

md
ZWNJ (U+200C) is used to prevent two characters from joining. Meaningful uses in Persian:

- **Verb prefixes**: می‌خواهم (I want), می‌شود (becomes), می‌توانم (I can)
- **Compound words**: کتاب‌ها (books), خانه‌ها (houses)
- **After certain particles**: از او، با او، در او
- **Before certain suffixes**: نمی‌روم، نمی‌خوانم

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/persian-typography.md (reported line 29)May include surrounding context.

md
ZWNJ (U+200C) is used to prevent two characters from joining. Meaningful uses in Persian:

- **Verb prefixes**: می‌خواهم (I want), می‌شود (becomes), می‌توانم (I can)
- **Compound words**: کتاب‌ها (books), خانه‌ها (houses)
- **After certain particles**: از او، با او، در او
- **Before certain suffixes**: نمی‌روم، نمی‌خوانم

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/persian-typography.md (reported line 30)May include surrounding context.

md
ZWNJ (U+200C) is used to prevent two characters from joining. Meaningful uses in Persian:

- **Verb prefixes**: می‌خواهم (I want), می‌شود (becomes), می‌توانم (I can)
- **Compound words**: کتاب‌ها (books), خانه‌ها (houses)
- **After certain particles**: از او، با او، در او
- **Before certain suffixes**: نمی‌روم، نمی‌خوانم

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/persian-typography.md (reported line 32)May include surrounding context.

md
ZWNJ (U+200C) is used to prevent two characters from joining. Meaningful uses in Persian:

- **Verb prefixes**: می‌خواهم (I want), می‌شود (becomes), می‌توانم (I can)
- **Compound words**: کتاب‌ها (books), خانه‌ها (houses)
- **After certain particles**: از او، با او، در او
- **Before certain suffixes**: نمی‌روم، نمی‌خوانم

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/generate_docx.py (reported line 445)May include surrounding context.

python
F demonstrating all features."""
    gen = PersianPDFGenerator(
        title="گزارش نمونه — تولید سند فارسی",
        output_path=output_path
    )

    # Title
    gen.add_title("گزارش نمونه تولید سند فارسی")

    # Mixed content paragraph
    gen.add_paragraph(
        "نسخه Next.js 16.0.7 منتشر شد. این نسخه شامل قابلیت‌های جدید متعددی است.",
        mixed_parts=[
            {'text': 'نسخه ', 'type': 'persian'},
            {'text': 'Next.js', 'type': 'latin'},
            {'text': ' 16.0.7 منتشر شد. این نسخه شامل قابلیت‌های جدید متعددی است.', 'type': 'persian'},
        ]
    )

    # Technical content
    gen.add_paragraph(
        "دستور نصب: npm install @tanstack/react-query",
        mixed_parts=[
            {'text': 'دستور نصب: ', 'type': 'persian'},
            {'text': 'npm install @tanstack/react-query', 'type': 'mono'

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/generate_pdf.py (reported line 323)May include surrounding context.

python
F demonstrating all features."""
    gen = PersianPDFGenerator(
        title="گزارش نمونه — تولید سند فارسی",
        output_path=output_path
    )

    # Title
    gen.add_title("گزارش نمونه تولید سند فارسی")

    # Mixed content paragraph
    gen.add_paragraph(
        "نسخه Next.js 16.0.7 منتشر شد. این نسخه شامل قابلیت‌های جدید متعددی است.",
        mixed_parts=[
            {'text': 'نسخه ', 'type': 'persian'},
            {'text': 'Next.js', 'type': 'latin'},
            {'text': ' 16.0.7 منتشر شد. این نسخه شامل قابلیت‌های جدید متعددی است.', 'type': 'persian'},
        ]
    )

    # Technical content
    gen.add_paragraph(
        "دستور نصب: npm install @tanstack/react-query",
        mixed_parts=[
            {'text': 'دستور نصب: ', 'type': 'persian'},
            {'text': 'npm install @tanstack/react-query', 'type': 'mono'

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_docx.py (reported line 502)May include surrounding context.

python
gen.add_ordered_list([
        'نصب Node.js نسخه 20.11.0 یا بالاتر',
        'اجرای دستور npm install',
        'تنظیم فایل محیط .env',
        'اجرای دستور npm run dev',
    ])

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_pdf.py (reported line 380)May include surrounding context.

python
gen.add_ordered_list([
        'نصب Node.js نسخه 20.11.0 یا بالاتر',
        'اجرای دستور npm install',
        'تنظیم فایل محیط .env',
        'اجرای دستور npm run dev',
    ])

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/validate_doc.py (reported line 41)May include surrounding context.

python
ect page breaks
- Broken spacing
- Corrupted ZWNJ usage
"""

import argparse
import re
import sys
from typing import List, Dict, Tuple, Optional
from pathlib import Path


# Unicode ranges for Persian/Arabic script
PERSIAN_RANGE = re.compile(r'[؀-ۿݐ-ݿࢠ-ࣿﭐ-﷿ﹰ-]')
LATIN_RANGE = re.compile(r'[A-Za-z]')
DIGIT_PERSIAN = re.compile(r'[۰-۹]')
DIGIT_LATIN = re.compile(r'[0-9]')
ZWNJ = '‌'
ZWSP = '​'
LRM = '‎'
RLM = '‏'


class PersianDocValidator:
    """Validates Persian documents for RTL correctness."""

    def __init__(self):
        self.issues: List[Dict] = []
        self.warnings: List[Dict] = []

    def validate_text(self, text: str, context: str = "") -> Dict:
        """Validate a text string for RTL correctness.

        Returns a dict with:
        - valid: bool (True if no issues)
        - issues: list of found issues
        - warnings: list of warnings
        """
        self.issues = []
        self.warnings = []

        self._check_reversed_engl

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The phrase "fix direction" is too generic and could match unrelated user intents, causing accidental invocation of the skill on ambiguous requests. In agent systems, ambiguous triggers can be abused to steer execution into tools or workflows the user did not intend.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The phrase "fix direction" is too generic and could match unrelated user intents, causing accidental invocation of the skill on ambiguous requests. In agent systems, ambiguous triggers can be abused to steer execution into tools or workflows the user did not intend.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The analyzer instructions are materially misaligned with the skill manifest: instead of generating or repairing Persian RTL documents, the file directs the agent to analyze benchmark/eval results. In a skill-loading system, this kind of scope mismatch can cause the agent to perform unintended tasks, ignore the user's requested document work, or leak internal evaluation focus into production behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title explicitly scopes the skill to a Persian document generator, which imposes a language-specific behavior in the skill's natural-language instructions. The file does not indicate that users can choose another language or opt into the Persian-only constraint, which matches the language/locale policy-violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instructions state that the comparator evaluates versions of a Persian document generator skill, which hard-codes a language-specific context. Under the policy, language or locale constraints should either be optional for the user or clearly documented as justified; this file does not provide that justification or opt-in framing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file explicitly frames the skill as evaluating Persian document generation and RTL correctness, which imposes a specific language/locale expectation. Under the policy rule, locale constraints should either provide user opt-in or be clearly documented as a justified region- or language-specific tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.