Back to skill

Security audit

Word To Jpg

Security checks for vulnerabilities and agentic risk

Overview

This Word-to-JPG converter matches its stated purpose, but it needs review because it silently deletes existing images in its output folder and leaves document copies in predictable temporary files.

Review before installing. Use this only for documents you intend to convert, avoid storing unrelated images in ~/.openclaw/media/outbound/word-images, and be aware that converted document content may remain as JPG outputs and as a copied source file under ~/.openclaw/workspace/temp/source.docx. Prefer a revised version that uses per-run output folders, cleans temporary files reliably, and pins dependencies.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:29-32, SKILL.md:68, scripts/word-to-jpg-converter.py:5
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Vulnerable code:

powershell
## Dependencies

Install before first use:
pip install comtypes pymupdf -q

The script documents the same unversioned installation command:

python
Dependencies: pip install comtypes pymupdf -q

Technical Analysis

The installation instructions retrieve the latest available versions of comtypes and pymupdf without version constraints, integrity hashes, a lock file, or a trusted package index explicitly configured for the project.

Python packages can execute code during installation and whenever imported. Consequently, the effective code trusted by the Skill can change after this Skill has been audited. This also makes installations non-reproducible and exposes users to compromised future releases, dependency-resolution attacks, or a malicious package supplied through an improperly configured package index.

The package names in the audited instructions are not apparent typos, and the audit found no evidence that their current releases are malicious. The finding concerns the unsafe dependency acquisition process rather than confirmed malicious package content.

Attack Path

  1. An attacker compromises a future release of one of the named dependencies, its publisher account, or a package index available to the victim.
  2. A user follows the documented pip install comtypes pymupdf -q instruction.
  3. Package resolution selects the attacker-controlled release because no reviewed version or hash is required.
  4. Malicious package code executes during installation or when the converter imports comtypes.client or fitz.
  5. The payload receives the permissions of the Python or pip process.

Impact Assessment

Successful exploitation permits arbitrary code executi ...[truncated 359 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create a reviewed dependency manifest that pins exact versions, for example:
    text
    comtypes==<reviewed-version> --hash=sha256:<reviewed-hash>
    PyMuPDF==<reviewed-version> --hash=sha256:<reviewed-hash>
    
  2. Install with hash verification:
    powershell
    python -m pip install --require-hashes -r requirements.txt
    
  3. Generate and retain a lock file through a controlled dependency-update process.
  4. Configure an explicitly trusted package index rather than relying on ambient pip configuration.
  5. Scan and test dependency updates before changing pinned versions.
  6. Run installation and conversion without administrator privileges.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/word-to-jpg-converter.py:45
Finding

Predictable Temporary Files Retain Sensitive Document Content

Content
View full analysis

Vulnerability Details

File Location: scripts/word-to-jpg-converter.py:16-18, scripts/word-to-jpg-converter.py:45-50, scripts/word-to-jpg-converter.py:102-105, scripts/word-to-jpg-converter.py:122-133
Vulnerability Type: Unsafe temporary-file handling and incomplete cleanup
Risk Level: Medium

Vulnerable code:

python
BASE_DIR = os.path.expanduser("~/.openclaw")
OUTPUT_DIR = os.path.join(BASE_DIR, "media/outbound/word-images")
TEMP_DIR = os.path.join(BASE_DIR, "workspace/temp")
INBOUND_DIR = os.path.join(BASE_DIR, "media/inbound")
python
def copy_to_temp(source_path):
    """Copy file to temporary directory (avoids non-ASCII path issues)."""
    os.makedirs(TEMP_DIR, exist_ok=True)
    temp_path = os.path.join(TEMP_DIR, "source.docx")
    shutil.copy2(source_path, temp_path)
    return temp_path
python
# Delete temporary PDF
if os.path.exists(pdf_path):
    os.remove(pdf_path)
    print(f"Temporary PDF cleaned")
python
# Copy to temporary directory
temp_path = copy_to_temp(source_path)
print(f"Copied to temporary directory")

# Convert to PDF
pdf_path = os.path.join(OUTPUT_DIR, "temp.pdf")
if not word_to_pdf(temp_path, pdf_path):
    return False

# Convert to JPG
page_count = pdf_to_jpg(pdf_path, OUTPUT_DIR)

Technical Analysis

Every conversion copies its source document to the predictable path ~/.openclaw/workspace/temp/source.docx. This copied Word document is never deleted, including after a successful conversion. The intermediate PDF also uses the predictable name temp.pdf and is removed only after pdf_to_jpg reaches its cleanup statements. Export or rendering exceptions can therefore leave another readable copy behind.

Fixed shared names also make concurrent conversions unsafe. Two converter processes can overwrite or consume each other's temporary files, producing incorrect output or exposing one conversion's con ...[truncated 1431 chars]

Remediation
View remediation

Remediation Suggestions

  1. Use tempfile.TemporaryDirectory to create an unpredictable directory for each conversion.
  2. Store both the copied document and intermediate PDF inside that per-run directory.
  3. Wrap the complete conversion process in try/finally or a temporary-directory context manager so cleanup occurs after success and failure.
  4. Ensure the temporary directory and files are accessible only to the current user.
  5. Preserve the original extension when copying .doc files instead of always naming the copy source.docx.
  6. Avoid shared intermediate filenames so concurrent conversions cannot overwrite each other's data.
  7. On Windows, explicitly close Word documents and PyMuPDF handles before cleanup, including in exception paths.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/word-to-jpg-converter.py:81
Finding

Conversion Deletes Unrelated Images from a Shared Output Directory

Content
View full analysis

Vulnerability Details

File Location: scripts/word-to-jpg-converter.py:81-84
Vulnerability Type: Overbroad destructive file cleanup
Risk Level: Medium

Vulnerable code:

python
# Clean up old image files
for f in os.listdir(output_dir):
    if f.endswith(('.jpg', '.png')):
        os.remove(os.path.join(output_dir, f))

Technical Analysis

Before rendering a document, the converter deletes every lowercase .jpg and .png entry in the fixed output directory. It does not verify that a file was generated by this Skill, belongs to a previous run, or matches the page_N.jpg naming convention.

As a result, unrelated images placed in ~/.openclaw/media/outbound/word-images are destroyed. Because the directory is shared across runs, one conversion can also delete another concurrent conversion's output. There is no transactional output process, per-job namespace, ownership manifest, or user confirmation.

os.listdir returns directory-entry names, and os.remove follows normal filesystem semantics. If an attacker with write access to the output directory can place a suitable link or file entry there, the cleanup operation may also target content reachable through that entry, subject to operating-system behavior and the converter user's permissions.

Attack Path

  1. A user or another workflow stores JPG or PNG files in the fixed word-images directory.
  2. The converter begins processing a Word document.
  3. pdf_to_jpg enumerates the directory.
  4. Every lowercase filename ending in .jpg or .png is passed to os.remove.
  5. Unrelated images are permanently deleted before new pages are written.

In a concurrent scenario, one conversion can execute this cleanup after another conversion has begun producing pages, deleting that other job's output and replacing it with pages from the current document.

Impact Assessment

Exploitation or accidental triggering causes deletion of image ...[truncated 361 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create a unique output directory for each conversion, such as a random job identifier beneath word-images.
  2. Do not delete arbitrary files from a shared output directory.
  3. If reuse is required, maintain a manifest of files created by the specific job and remove only those files.
  4. At minimum, restrict cleanup to validated regular files matching an exact generated-name pattern such as ^page_[1-9][0-9]*\.jpg$.
  5. Reject symbolic links and verify resolved paths remain inside the intended output directory before deletion.
  6. Write output to a staging directory and atomically publish the completed result to avoid partial or cross-job output.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'file_read' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'file_write' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Most of the user-facing instructions, trigger descriptions, and usage guidance are presented only in Chinese, which effectively forces a specific language for interaction and comprehension. The file does not offer an alternative language or explain that the skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad, generic requests like '转成图片' and '文档转图片', which can easily match ordinary user conversation and invoke the skill unintentionally. In this skill's context, accidental invocation is more dangerous because the skill is documented to automatically locate the latest received Word document and convert it, potentially acting on sensitive files without explicit user selection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The functionality description omits an important behavioral warning: the skill automatically finds the latest received Word document and writes output to a fixed directory. This can surprise users, cause unintended processing of sensitive documents, and leave derivative image files in a predictable location where they may persist or be accessed later.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script accepts a caller-supplied path and will open matching Word files from any accessible directory, not just the expected inbound area. In an agent environment, this broadens file access scope and can expose sensitive local documents to processing without meaningful boundary checks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Before conversion, the script unconditionally deletes every existing .jpg and .png file in the shared output directory. That creates unintended destructive side effects beyond the advertised task and can erase unrelated user data if the directory contains other images.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code removes existing JPG/PNG files without any explicit warning, prompt, or confirmation. This makes accidental data loss likely, especially because users would reasonably expect a converter to add outputs rather than silently delete prior images.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file description and runtime print messages are presented in Chinese, and the script does not provide any opt-in or language-selection mechanism. This can violate language/locale policy when skills are expected to avoid forcing a specific language unless documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.