Back to skill

Security audit

Document Formatting Automation Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a document-formatting helper with sloppy activation metadata, but it does not request sensitive access, persistence, hidden execution, or unsafe authority.

Before installing, be aware that the skill may activate too easily on generic words like styles or automation. It appears safe as a guidance-only document-formatting helper, but the publisher should narrow the triggers and clean up the evidence and localization text for better reliability.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger sentence is extremely broad and malformed, so it can match ordinary user requests that merely mention help or workflows rather than clearly invoking this specific skill. In an agent system, overbroad activation increases the chance of unintended routing, causing the skill to run in contexts it was not designed for and potentially override more appropriate handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger section lacks clear boundaries for when the skill should and should not activate, relying on broad productivity wording instead of precise document-formatting conditions. This increases the chance of unintended invocation across unrelated requests, which is especially risky in multi-skill environments where routing accuracy affects downstream behavior and user trust.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger sentence begins with a very common phrase ('Help me') and then appends generic task language, which makes accidental or overly broad invocation more likely. In an agentic system, ambiguous activation boundaries can cause the wrong skill to engage on unrelated user requests, leading to misrouting, confusing outputs, or inappropriate workflow execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad, generic, and include natural-language patterns that could cause the skill to activate in unintended contexts. In an agent ecosystem, ambiguous activation can route user requests to the wrong skill, causing inappropriate handling of content or accidental execution of workflows the user did not intend.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description and use conditions are broad enough that the agent could invoke this skill for many generic productivity or document-related requests beyond its intended scope. Over-broad activation increases the chance of accidental routing, which can expose users to irrelevant automation guidance, confuse task handling, or displace a more appropriate skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The keyword list contains common terms such as 'styles' and 'automation' that appear in many unrelated user requests, making unintended invocation likely. In an agent system, broad keywords can hijack routing decisions and cause this skill to activate outside document-formatting contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is broad and maps to common productivity terms without strong scoping constraints, which can cause the agent to invoke this skill for loosely related requests. Over-broad routing increases the chance of unintended delegation, causing incorrect handling of user tasks or overshadowing more appropriate skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The keyword list includes generic terms such as 'automation' and broad productivity phrases that are likely to match many unrelated prompts. This can lead to accidental activation, misrouting, and reduced reliability of the overall agent system, especially in environments with multiple overlapping skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The default prompt is constructed as a broad, natural-language invocation phrase tied to common work-productivity tasks, which increases the chance of accidental or implicit triggering during ordinary user conversation. Because implicit invocation is enabled, this overlap can cause the skill to activate outside clear user intent, potentially injecting its instructions or behavior into unrelated sessions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger description and examples are non-specific, truncated, and lack precise conditions for when the skill should activate. This ambiguity can cause accidental invocation from common language, reducing routing reliability and making the agent easier to steer into using the wrong skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

This file is presented as a zh-CN README, but key user-facing content such as the demand description, workflow description, keywords, and trigger phrases remains in English. That can amount to an implicit language constraint or inconsistent locale behavior without stating that users may choose their preferred language.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document frames the links under '来源证据' as evidence for demand around document formatting, find-and-replace, styles, and Word-like editing. However, nearly all listed links concern unrelated topics such as Rust disk usage, C++ character width, SSHD/docker, cookies, and design patterns, which contradicts the stated purpose of the evidence section rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example trigger phrases are vague, truncated, and malformed, which weakens activation precision and may train downstream routing toward poor-quality matches. While less severe than the broad description and keywords, unclear examples still increase the likelihood of accidental or inconsistent invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

该技能文件整体以中文呈现,且未说明可根据用户偏好切换语言或由用户选择输出语言。按照语言/locale 政策,若技能默认强制单一语言而不给用户选择,可能构成自然语言策略违规。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.