Back to skill

Security audit

Hwp Extract Pipeline

Security checks for vulnerabilities and agentic risk

Overview

This document-extraction skill appears purpose-related but needs review because it overstates PDF/OCR support and can execute local programs and write extracted contents to paths influenced by user input.

Install only if you trust the callers and can run it in a constrained workspace. Treat extracted document text as retained on disk, validate --id to a simple identifier, do not pass untrusted --venv paths, and do not rely on the advertised PDF/OCR behavior until it is implemented or the documentation is corrected.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/extract_hwp.py:165
Finding

Path Traversal Enables Arbitrary Relative File Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/extract_hwp.py:64
Finding

Untrusted Interpreter Path Allows Arbitrary Local Executable Launch

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description claims reliable PDF/scan extraction and OCR fallback, but the static finding indicates the implementation does not actually provide those capabilities and instead falls back differently. This mismatch is security-relevant because downstream agents may trust the advertised extraction guarantees, make decisions on incomplete or incorrect text, or skip safer handling paths under the false assumption that OCR/PDF parsing occurred.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises behavior that involves shell execution and writing files, but it does not declare any tool scope or permission boundaries in the manifest. This creates an authorization and transparency gap: an agent or user may invoke the skill without understanding that it can execute commands and persist data to disk, increasing the risk of unsafe file modification or command execution in broader runtime contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The operative usage instructions and behavior descriptions are provided in Korean only, with no indication that users may request another language. This can violate a language/locale policy when a skill forces a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/extract_hwp.py (reported line 25)May include surrounding context.

python
def run_cmd(cmd, timeout=30, env=None):
    try:
        p = subprocess.run(cmd, stdout=subprocess.PIPE, stderr=subprocess.PIPE, timeout=timeout, env=env)
        return p.returncode, p.stdout.decode('utf-8', errors='replace'), p.stderr.decode('utf-8', errors='replace')
    except subprocess.TimeoutExpired:
        return -1, '', 'timeout'

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script writes extracted document text to a predictable local JSON file named from the provided record ID, even though the skill is presented as an extraction pipeline rather than a persistence/export tool. This can silently retain sensitive document contents on disk, increasing the risk of unintended disclosure to other users, processes, logs, backups, or later workflow steps.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Extracted document text is written to a local JSON file without any user-facing disclosure or consent mechanism. In the context of HWP/HWPX/PDF extraction, the content is likely to include sensitive personal, legal, or business data, so silent local retention materially increases confidentiality risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The markdown states that extracted output is saved to disk, but it does not warn users about this filesystem side effect or clarify where data will persist. In document-processing workflows, silent persistence can expose sensitive contents, create unintended data retention, or overwrite files in shared workspaces if callers assume the operation is read-only.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The top-level documentation states the priority includes 'ocr(not implemented)', while the manifest says the pipeline attempts OCR with safe fallbacks. The actual code never performs OCR and instead falls back from HWP/HWPX handling directly to the strings command.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The code writes a temporary Python script to disk, marks it executable, and runs it as a subprocess to invoke pyhwp. This subprocess execution is only described internally in a code comment, not disclosed to the user via runtime messaging or the top-level usage documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.