Back to skill

Security audit

用于为Word文档开启并调整修订模式,添加、删除批注等功能

Security checks for vulnerabilities and agentic risk

Overview

The skill is aimed at DOCX review work, but its revision/comment behavior and temporary-file instructions could mislead users or alter documents unexpectedly.

Review this skill before installing if you need legally reliable Word comments or auditable Track Changes. Its DOCX editing purpose is legitimate, but users should verify output documents manually, avoid the documented fixed docx_temp workflow, and treat the script's comment helper as visible inline text insertion rather than a real Word comment.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:24
Finding

Predictable Shared Temporary Directory Enables File Injection, Disclosure, and Destructive Cleanup

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:24-26
Additional Locations: SKILL.md:71-72, SKILL.md:81, SKILL.md:135-136
Vulnerability Type: Unsafe temporary-directory handling
Risk Level: Medium

Vulnerable Code

bash
# SKILL.md:24-26
unzip -o document.docx -d docx_temp
cd docx_temp && zip -r ../output.docx . && cd .. && rm -rf docx_temp

The same fixed directory is used elsewhere:

bash
# SKILL.md:71-72
unzip -o document.docx -d docx_temp
cat docx_temp/word/comments.xml
bash
# SKILL.md:81
unzip -o document.docx -d docx_temp
bash
# SKILL.md:135-136
cd docx_temp && zip -r ../output.docx . && cd ..
rm -rf docx_temp

Technical Analysis

The documented workflow extracts untrusted DOCX archives into a predictable directory named docx_temp. It neither creates that directory securely nor verifies its ownership, contents, or isolation from another process. The -o option overwrites existing files without confirmation.

The repackaging command recursively archives everything in the directory, including stale or attacker-planted files that are not part of the current document. The final recursive deletion also acts on the shared predictable path without confirming that it is the directory created by the current operation.

This creates local race-condition and pre-positioning opportunities. Exploitation requires an attacker who can modify the working directory or race the workflow under the operating-system permissions of the user executing the commands.

Attack Path

  1. The attacker predicts that processing will use ./docx_temp.
  2. Before extraction, the attacker creates or populates that directory with crafted or sensitive content. Alternatively, the attacker modifies it while processing is in progress.
  3. The instructed unzip -o operation writes into the attacker-influenced shared directory and silently overwrites colliding fil ...[truncated 1106 chars]
Remediation
View remediation

Remediation Suggestions

  • Create a unique private directory for every invocation with mktemp -d.
  • Register a cleanup trap immediately after successful directory creation.
  • Quote all path expansions.
  • Verify that the cleanup target is nonempty, expected, and owned by the current process before recursive deletion.
  • Reject archive entries with absolute paths or .. traversal components before extraction.
  • Repackage only explicitly expected OOXML files rather than recursively including every directory entry.
  • Prevent concurrent runs from sharing extraction state.
  • Consider using a DOCX/ZIP library that validates archive members and writes to a controlled destination.

Example hardened shell workflow:

bash
tmpdir="$(mktemp -d)" || exit 1
cleanup() {
    if [ -n "${tmpdir:-}" ] && [ -d "$tmpdir" ]; then
        rm -rf -- "$tmpdir"
    fi
}
trap cleanup EXIT HUP INT TERM

unzip -- document.docx -d "$tmpdir"
(
    cd -- "$tmpdir" || exit 1
    zip -r -- ../output.docx \
        '[Content_Types].xml' _rels docProps word
)

Archive member names should be validated before the extraction step because command quoting alone does not prevent malicious archive-entry traversal in vulnerable extraction tools.

Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

代码总体方向与声明领域相关,确实是一个面向 Word .docx 的修订/修改脚本,不存在明显越权、外部资源访问或无关主功能。但声明的功能范围明显大于实际实现。首先,批注功能名不副实:add_comment 只是找到文本后在段落中追加普通字符串“[comment]”,并非 Word 批注结构,也没有删除、查看批注的实现。其次,虽然存在 enable_track_changes、add_insertion、add_deletion 等函数,但主程序并未调用启用修订跟踪的函数,CLI 也只处理 --add 替换;因此“支持修订模式”仅部分成立。再者,声明中特别提到红字修订,而实现中插入修订是绿色下划线,删除修订才是红色删除线,和描述不完全一致。综合看,这是描述与实际能力存在实质差距的情况,应判定为 mismatch。

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

The documented command chain includes destructive cleanup with 'rm -rf' after multiple shell operations joined by '&&'. In a skill context that may be copied or adapted by an agent, this increases the risk of unsafe deletion, especially if the working directory changes unexpectedly or variables/paths are later generalized from fixed examples.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
1. 解压文档:`unzip -o document.docx -d docx_temp`
2. 编辑 XML 文件
3. 重新打包:`cd docx_temp && zip -r ../output.docx . && cd .. && rm -rf docx_temp`

---

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description and trigger/invocation guidance are written as a Chinese-only skill description, and the content recommends specific language usage patterns without offering a user language choice. This can violate language/locale policy when a skill implicitly constrains interaction to one language absent explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module-level claim says it implements 'true track changes' by directly manipulating OOXML, but several code paths do not create real Word revision/comment structures. add_insertion and add_deletion only add visually styled text at the end of the document, and add_comment appends bracketed text inline, which can mislead downstream users or workflows into believing edits are auditable when they are not.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The function is presented as adding a Word comment, but it merely appends bracketed text into the document body. In a document-review skill, this is security-relevant because users may rely on comments for review, legal approval, or audit separation; embedding the text directly changes document content and can leak reviewer notes into the final visible document.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.