Back to skill

Security audit

Gongwen Format

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused Chinese official-document formatting helper with disclosed local document-processing scripts and no evidence of hidden, persistent, or unrelated behavior.

Install dependencies in a virtual environment, consider pinning reviewed versions of python-docx and olefile, and run the scripts only on documents you intend to process. Review generated .docx output manually because the formatter changes layout and fonts while leaving some header/footer work for Word or WPS.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:99
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 99
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code Snippet

markdown
Script dependencies: `pip install python-docx olefile` (`gongwen_checklist.py` needs no extra packages).

Technical Analysis

The skill instructs users or agents to install python-docx and olefile without specifying reviewed versions or cryptographic hashes. Consequently, installation results depend on mutable package-index state at the time the command is run.

If an upstream package, maintainer account, release process, or configured package index is compromised, pip could retrieve a malicious or unexpectedly changed release. Python package installation may execute package build logic, while malicious installed modules could execute later when imported by the bundled scripts.

No evidence indicates that the named packages are currently malicious. The risk arises from the unsafe, non-reproducible dependency installation practice.

Attack Path

  1. An attacker compromises an upstream dependency release, its publishing account, or a package index used by the environment.
  2. A user or agent follows the instruction in SKILL.md and runs:
    bash
    pip install python-docx olefile
    
  3. Because no version or hash is pinned, pip resolves the attacker-controlled or compromised release.
  4. Malicious installation logic may run during installation, or malicious module code may run when format_gongwen_docx.py or read_doc_text.py imports the package.
  5. The payload executes with the privileges of the user or automation account performing the installation or running the script.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing or script-running account. The resulting scope may include access to documents processed by the skill, files readable or writable by that account, environment variables, and other ...[truncated 136 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the free-form installation command with a reviewed lock file containing exact versions:
    text
    python-docx==<reviewed-version>
    olefile==<reviewed-version>
    
  2. Record SHA-256 hashes for all direct and transitive artifacts and require verification:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Generate and review the lock file in a controlled build process, including all transitive dependencies.
  4. Use an approved package index or internal artifact repository rather than an arbitrary environment-configured source.
  5. Install dependencies inside an isolated virtual environment or container under a non-privileged account.
  6. Periodically scan and deliberately update pinned dependencies after reviewing advisories and release provenance.
  7. Document the expected Python and pip versions to improve reproducibility.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill explicitly instructs the agent to run local scripts that write output files, including creating reformatted .docx documents, but it does not declare any tool scope or allowed-tools restrictions. That mismatch can enable unintended file writes if an agent auto-executes the workflow, especially because user-supplied filenames and documents are part of the documented usage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The instruction 'Keep wording formal, concise, and administrative in tone' is paired with a skill description that is exclusively for Chinese official documents, effectively constraining output language/locale and style to a specific organizational context. The file does not offer any user choice or opt-in for language/locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The default prompt instructs use of the skill to make documents comply with Chinese official document standards, including GB/T 9704-2012 and local 公文 formatting requirements. This imposes a specific language/locale and regulatory context by default, without indicating user choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code hard-codes Chinese fonts and gongwen formatting rules throughout the document body and headings, making the skill effectively enforce a specific language/locale formatting policy. The file does not present this as an explicit user choice or document a justified locale restriction beyond the brief module description, so the locale constraint is imposed rather than offered.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file is a natural-language guideline that prescribes Chinese government document formatting (Gongwen, GB/T 9704-2012) and uses Chinese-only formatting terms throughout, but it does not explicitly state that these rules apply only when the user is preparing PRC official documents or has opted into that locale. Under the language/locale policy, forcing a specific locale without clear opt-in or documented regional scope can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This Python file emits checklist text containing Chinese-specific document terms and labels such as 命令, 令, and XXXXX纪要, and the description does not indicate that the skill is intentionally limited to a Chinese-language or China-specific document workflow. Under the policy, forcing a specific language or locale without opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.