other
- Location
ods.py:66- Finding
Existing Document Headers Are Unconditionally Overwritten
- Content
View full analysis
Vulnerability Details
File Location:
ods.py, lines 66–68 and 131–135
Vulnerability Type: Unintended document content modification
Risk Level: MediumVulnerable Code
python header = section.header.paragraphs[0] header.text = "Office Document Specialist Suite" header.alignment = WD_ALIGN_PARAGRAPH.LEFTThe affected function is invoked while processing existing documents:
python def cmd_style_doc(input_file: Path, output_file: Path, landscape: bool): doc = Document(input_file) apply_advanced_layout(doc, landscape=landscape) configure_styles(doc) doc.save(output_file)Technical Analysis
apply_advanced_layout()unconditionally assigns fixed branding to the first paragraph of the first section header. Thestyle-doccommand calls this function for an existing user-supplied document, so any content previously stored in that header paragraph is replaced.The command provides no option to preserve the original header or explicitly consent to branding. The documented purpose of
style-docis to apply formatting, and the skill documentation does not disclose that existing header content will be replaced.This is not skill-instruction hijacking because it does not alter the agent's instructions or safety constraints. It is an application-level integrity issue involving unexpected modification of user content.
Attack Path
- A user or agent supplies an existing
.docxfile containing an important header, such as a company name, confidentiality notice, document identifier, or classification marking. - The user invokes
python ods.py style-doc input.docx --output styled-output.docx. cmd_style_doc()loads the document and callsapply_advanced_layout().- The first header paragraph is replaced with
Office Document Specialist Suite. - The altered document is saved without warning that the original header was removed.
Impact Assessment
...[truncated 481 chars]
- A user or agent supplies an existing
- Remediation
View remediation
Remediation Suggestions
- Preserve existing header content by default when processing an existing document.
- Remove the hard-coded suite name from the general layout function.
- If a custom header is required, expose an explicit option such as
--header-text. - Require an affirmative option such as
--replace-headerbefore overwriting existing content. - Detect nonempty headers and either retain them or stop with a clear warning.
- Separate document styling from content insertion so formatting operations cannot silently change textual content.
- Add tests confirming that
style-docpreserves headers unless replacement is explicitly requested. - Document all content-changing behavior in
SKILL.md.
