Back to skill

Security audit

Word DOCX Formatting Repair

Security checks for vulnerabilities and agentic risk

Overview

The skill is a straightforward DOCX repair guide with some broad trigger wording, but it does not show hidden code, credential use, persistence, or data exfiltration.

Installers should be aware that the skill may be invoked broadly for Word or DOCX topics, so it is best used when you actually want DOCX formatting diagnosis or repair. For sensitive legal or business documents, keep the original file, work on a copy, and confirm before accepting tracked changes, deleting comments, or making direct OOXML edits.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger sentences are generic and repetitive enough that the skill could be invoked by loosely related Word or document-automation requests, rather than only when the user explicitly wants this helper. In an agent ecosystem, overly broad activation increases the chance of unintended routing, which can lead to incorrect actions, confusion, or mishandling of user documents and formatting workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The README explicitly describes SKILL.md as 'English Codex-valid skill instructions,' which indicates an English-language requirement in the skill's operative instructions. There is no accompanying statement that users may choose their preferred language or that English is optional, so this may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad, generic, and partly templated in a way that could cause accidental or overly eager invocation of the skill when a user mentions Word or DOCX formatting issues in passing. In an agent ecosystem, ambiguous triggers increase the chance that the skill activates outside the user's intended scope, which can lead to inappropriate workflow execution or mishandling of sensitive business or legal documents.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description and usage scope are broad enough that it may trigger on common Word/DOCX-related requests outside the intended repair/formatting niche. Over-broad activation can cause the wrong skill to take control of a conversation, leading to inappropriate guidance, unnecessary file-handling suggestions, or expanded access to potentially sensitive document workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger keyword list lacks boundary conditions, disambiguation, and negative matches, so ordinary mentions of terms like 'docx', 'styles', or 'microsoft word' may activate the skill unintentionally. In an agent environment, this increases the chance of misrouting user requests and applying document-oriented workflows where they are not appropriate, especially around sensitive legal or business files.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill enables implicit invocation without any visible trigger constraints, which can cause the agent to activate this capability in broader contexts than intended. Because this skill is designed to inspect and repair DOCX files, ambiguous auto-selection could expose document contents to an unnecessary tool path or cause unintended modifications when a user did not explicitly request document-repair behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger sentences are overly broad and include natural-language phrasing that could match ordinary user requests rather than a clear, explicit tool invocation. This can cause unintended activation of the skill in contexts where the user did not deliberately opt in, increasing the chance that the agent applies DOCX-specific workflows or assumptions inappropriately.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This file is presented as a Chinese README, but key user-facing content including the title, demand description, workflow description, and trigger phrases is written in English. That can amount to forcing a language/locale on users without opt-in, and the document does not indicate that users may choose their preferred language.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The example trigger phrases use highly generic help-seeking language that overlaps with normal user requests, which can reinforce over-triggering behavior in systems that learn from examples. While less severe than the broad metadata and keyword issues, these examples still increase accidental invocation risk and reduce precision of skill selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The usage signals and trigger examples are written as English-only invocation patterns, which biases activation toward English phrasing without indicating multilingual support or user choice. This is dangerous mainly from a safety and reliability standpoint because it can create inconsistent triggering behavior, exclude non-English users, or cause the agent to overfit to exact English phrasings.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.