Back to skill

Security audit

Word Docs

Security checks for vulnerabilities and agentic risk

Overview

This DOCX skill uses normal document-rendering tools and local file outputs, with install-time cautions but no evidence of hidden data theft or destructive behavior.

Install only in a trusted or isolated environment, approve any sudo/system package command yourself, and avoid pointing the renderer at an output directory containing files you need to preserve because page images can be replaced.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:34
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 34-39
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

text
uv pip install python-docx pdf2image
text
python3 -m pip install python-docx pdf2image

Technical Analysis

The documented installation commands retrieve and install python-docx and pdf2image without version constraints, integrity hashes, or a repository lockfile. Consequently, the package versions and code installed can change over time, making installation non-reproducible.

This creates supply-chain exposure if a dependency release or its distribution channel is compromised. An affected package could execute attacker-controlled code during installation or later when imported by scripts/render_docx.py. Exploitation requires the user or agent to follow these dependency-installation instructions while the affected release is available through the configured package index.

Attack Path

  1. An attacker compromises an upstream dependency release, maintainer account, or configured Python package index.
  2. The attacker publishes a malicious version of python-docx or pdf2image.
  3. A user or agent follows the installation command in SKILL.md.
  4. Because no version or hash is pinned, the package manager resolves and downloads the malicious release.
  5. Attacker-controlled code executes during package installation or when the rendering script imports the installed package.

Impact Assessment

Malicious dependency code would run with the privileges of the account performing the installation or invoking the rendering helper. It could potentially access files and credentials available to that account, alter generated documents or rendered output, execute local commands, or communicate over the network where permitted.

The practical scope is limited by the invoking account's operating-system permissions and any sandbox, container, or network restrictions. The audited project itself d ...[truncated 68 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin each Python dependency to a reviewed, exact version.
  • Maintain a lockfile generated by the selected dependency-management tool.
  • Require cryptographic hashes for downloaded distributions, such as through a hash-locked requirements file.
  • Install dependencies into a dedicated virtual environment rather than the system Python environment.
  • Use a trusted, explicitly configured package index and restrict dependency resolution to approved sources.
  • Review and update pinned dependencies through a controlled process that includes vulnerability scanning and integrity verification.
  • Require explicit user approval before an agent installs or upgrades third-party packages.
  • Where practical, isolate document conversion and rasterization inside a sandbox or container with minimal filesystem and network permissions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/render_docx.py (reported line 106)May include surrounding context.

python
check=False,
        stdout=subprocess.DEVNULL,
        stderr=subprocess.DEVNULL,
        env=os.environ.copy(),
    )

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill instructs the agent to use shell/system capabilities for package installation and document rendering, but it does not declare any explicit tool scope or permission boundaries. This increases the risk of unintended command execution or overbroad access because an agent may invoke environment and shell operations without a clear least-privilege contract.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

The skill includes a privileged installation command using 'sudo apt-get install', which normalizes elevation to root as part of routine workflow. In an agentic setting, encouraging privilege escalation is dangerous because a compromised or misused agent could alter the host system, install unintended packages, or expand the blast radius of command injection or operational mistakes.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

brew install libreoffice poppler

Ubuntu/Debian

sudo apt-get install -y libreoffice poppler-utils

text

If installation isn't possible in this environment, tell the user which dependency is missing and how to install it locally.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/render_docx.py (reported line 101)May include surrounding context.

python
def run_cmd_no_check(cmd: list[str]) -> None:
    subprocess.run(
        cmd,
        check=False,
        stdout=subprocess.DEVNULL,

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This code creates an output directory and writes PNG files into it, renaming generated files to fixed names like page-.png. While the CLI help mentions the output directory location, it does not clearly warn the user that the skill performs file writes and may replace existing page files in that directory.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.