Back to skill

Security audit

Word Docx Formatting Repair Helper

Security checks across malware telemetry and agentic risk

Overview

This is a document-formatting guidance skill with no executable code or hidden data access, though its activation wording is broader than ideal.

Install only if you want help with Word/DOCX formatting cleanup, styles, and find-and-replace workflows. Keep invocation specific, and when following any generated automation or bulk replacement advice, work on a copy of the document and review changes before saving over originals.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentences are generic and broad enough that the skill may activate for loosely related requests, increasing the chance of unsolicited document-editing guidance being applied in the wrong context. In an agent ecosystem, ambiguous activation can cause misrouting, unexpected automation suggestions, or unintended handling of sensitive document workflows.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The README promotes document-editing automation but does not warn that workflows may modify user documents, which can lead to accidental overwrites, formatting corruption, or irreversible changes if users follow the guidance without safeguards. Because office, legal, and documentation users often work on important files, omission of backup/review warnings materially raises operational risk.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description and usage guidance use broad terms like work-productivity, document formatting, and styles without clear boundaries on when this skill should or should not activate. In an agentic environment, this can cause the skill to be selected for many ordinary requests outside its narrow purpose, increasing the chance of misrouting, unwanted instruction injection into unrelated tasks, or accidental override of more appropriate skills.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The keyword triggers are highly generic and include common terms such as styles, automation, and find replace, which appear in many unrelated contexts. This overbreadth can cause unintended activation, making the skill available in contexts where its instructions are not relevant and potentially interfering with safer or more specialized behaviors.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill description is broad enough to overlap with many ordinary productivity requests, which can cause the agent to invoke this skill when a more specific or safer skill would be more appropriate. Over-broad routing is dangerous because it increases unintended activation, expands the skill’s effective authority, and may lead to irrelevant or lower-quality outputs in contexts the author did not intend.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The keyword list contains generic terms like 'automation' and broad workplace phrases that are likely to match many unrelated requests. This increases the chance of accidental triggering and prompt-surface expansion, which can interfere with correct skill selection and expose downstream workflows to unintended inputs.

Vague Triggers

Low
Confidence
80% confidence
Finding
The example trigger phrases are highly generic and provide no counterexamples or guardrails, so they teach the router to activate the skill for loosely related requests. While less severe than the broad description and keyword list, these examples still contribute to over-triggering and ambiguous routing behavior.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt is a vague, catch-all invocation phrase that can cause the skill to be selected in situations beyond its intended scope. Combined with allow_implicit_invocation: true, this increases the chance of unintended routing, prompt-surface expansion, and the skill influencing unrelated user requests without explicit consent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentences are so broad and malformed that they can match ordinary user requests unrelated to a narrowly scoped Word formatting helper. Overbroad activation increases the chance the skill is invoked in unintended contexts, which can cause misrouting, irrelevant automation, and accidental disclosure of user context to a skill that was not the best fit.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.