Back to skill

Security audit

福昕 Office 助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Fuxin Office routing and automation skill whose document-editing behavior is purpose-aligned and bounded by preflight, window checks, and undo guidance.

Install only if you intend to let the agent operate on Fuxin Office documents through FuxinAiService. It can modify Word, Excel, and PowerPoint files after user-directed write requests, so keep the correct document active and use the documented save confirmations and Ctrl+Z undo guidance when needed.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Confidence
95% confidence
Finding
触发词列表包含“Office”“预检”“总结文档”等高度泛化表达,容易在用户并未明确请求该技能时被路由进来。作为“唯一入口”技能,一旦误触发,后续还具备跨产品编排和写操作能力,会放大误执行、误改文档和错误窗口操作的风险。

Vague Triggers

Medium
Confidence
89% confidence
Finding
“跨产品 / 多步骤 / 未归类”被作为路由条件,其中“未归类”缺乏可验证边界,意味着大量模糊请求都可能被吸入该总入口流程。该技能又被设计为内部参考文档的统一编排层,因此模糊路由会增加错误工具选择、错误产品预检和不符合用户意图的写入操作概率。

Vague Triggers

Medium
Confidence
90% confidence
Finding
The document recommends defining an enterprise custom tool around a single natural-language trigger phrase, but provides no routing boundaries, disambiguation rules, or exclusion conditions. In a top-level routing skill, this can cause ordinary user requests to be misclassified as privileged custom workflows, leading to unintended document modifications, report generation, or multi-step actions being executed under the wrong intent.

Static analysis

No suspicious patterns detected.