Back to skill

Security audit

Office Document Specialist Suite 1.0.2

Security checks for vulnerabilities and agentic risk

Overview

This Word-document skill is not malicious, but it overstates its Office-suite capabilities and can silently replace headers or footers in documents it restyles.

Review this skill before installing if you expect a full Office suite or need to preserve existing document headers, footers, confidentiality labels, or corporate branding. Use it only for .docx workflows, avoid running it directly on important originals, and prefer pinned dependencies or a reviewed environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Warning
Location
ods.py:66
Finding

Existing Document Headers Are Unconditionally Overwritten

Content
View full analysis

Vulnerability Details

File Location: ods.py, lines 66–68 and 131–135
Vulnerability Type: Unintended document content modification
Risk Level: Medium

Vulnerable Code

python
header = section.header.paragraphs[0]
header.text = "Office Document Specialist Suite"
header.alignment = WD_ALIGN_PARAGRAPH.LEFT

The affected function is invoked while processing existing documents:

python
def cmd_style_doc(input_file: Path, output_file: Path, landscape: bool):
    doc = Document(input_file)
    apply_advanced_layout(doc, landscape=landscape)
    configure_styles(doc)
    doc.save(output_file)

Technical Analysis

apply_advanced_layout() unconditionally assigns fixed branding to the first paragraph of the first section header. The style-doc command calls this function for an existing user-supplied document, so any content previously stored in that header paragraph is replaced.

The command provides no option to preserve the original header or explicitly consent to branding. The documented purpose of style-doc is to apply formatting, and the skill documentation does not disclose that existing header content will be replaced.

This is not skill-instruction hijacking because it does not alter the agent's instructions or safety constraints. It is an application-level integrity issue involving unexpected modification of user content.

Attack Path

  1. A user or agent supplies an existing .docx file containing an important header, such as a company name, confidentiality notice, document identifier, or classification marking.
  2. The user invokes python ods.py style-doc input.docx --output styled-output.docx.
  3. cmd_style_doc() loads the document and calls apply_advanced_layout().
  4. The first header paragraph is replaced with Office Document Specialist Suite.
  5. The altered document is saved without warning that the original header was removed.

Impact Assessment

...[truncated 481 chars]

Remediation
View remediation

Remediation Suggestions

  • Preserve existing header content by default when processing an existing document.
  • Remove the hard-coded suite name from the general layout function.
  • If a custom header is required, expose an explicit option such as --header-text.
  • Require an affirmative option such as --replace-header before overwriting existing content.
  • Detect nonempty headers and either retain them or stop with a clear warning.
  • Separate document styling from content insertion so formatting operations cannot silently change textual content.
  • Add tests confirming that style-doc preserves headers unless replacement is explicitly requested.
  • Document all content-changing behavior in SKILL.md.

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Dependency Installation Is Mutable and Not Integrity-Verified

Content
View full analysis

Vulnerability Details

File Location: requirements.txt, lines 1–2; setup.sh, lines 7–8
Vulnerability Type: Unpinned and unhashed third-party dependencies
Risk Level: Low

Vulnerable Code

requirements.txt:

text
python-docx>=1.1.2
lxml>=5.3.0

setup.sh:

bash
python -m pip install --upgrade pip
python -m pip install -r requirements.txt

Technical Analysis

The dependency constraints specify only minimum versions. Each installation can therefore resolve to different future releases. No hashes or lock file are provided to verify that downloaded artifacts match versions reviewed by the project.

The setup script also upgrades pip without pinning or integrity verification, introducing another mutable component into the installation process. Python package installation may execute package build or installation logic with the privileges of the user running the script.

The reviewed files contain no evidence of dependency confusion, typosquatting, a malicious package, or an untrusted custom package index. python-docx and lxml are consistent with the imports in ods.py. This finding is consequently a supply-chain hardening weakness rather than proof of a compromised dependency.

Attack Path

  1. A user follows the installation instructions and runs setup.sh.
  2. pip contacts its configured package index and resolves any releases satisfying the lower-bound constraints.
  3. A future compromised release, compromised index, or maliciously configured package source could provide an unsafe artifact.
  4. pip downloads and installs that artifact into .venv.
  5. Package build or installation behavior executes with the invoking user's privileges, and imported dependency code subsequently runs when ods.py is used.

Exploitation depends on an external supply-chain compromise or an attacker-controlled pip configuration; the project itself does not establish such control.

...[truncated 547 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin dependencies to exact, reviewed versions rather than minimum versions.
  • Generate a lock file containing hashes for all direct and transitive dependencies.
  • Install with hash enforcement, such as pip install --require-hashes -r requirements.txt.
  • Pin pip to a reviewed version or avoid upgrading it automatically during setup.
  • Use an explicitly trusted package index and prevent unexpected fallback to additional indexes.
  • Regularly scan dependencies for published vulnerabilities and update pins through a controlled review process.
  • Prefer prebuilt, verified wheels where appropriate to reduce execution of arbitrary build logic.
  • Document the supported Python and dependency versions to make installations reproducible.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code uses python-docx to create and restyle Word documents, adding margins, headers/footers, page numbers, and preset styles, plus generating a report template. This fits a narrow subset of 'creating/editing Word documents' and automated reporting templates. However, the declared description materially overstates the capability by presenting a multi-application Microsoft Office suite covering Word, Excel, and PowerPoint, with analysis and document management functions. None of those broader capabilities appear in the supplied code chunk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file contains multiple user-facing strings in Dutch for document content, status messages, and CLI help text, but provides no option to choose language or locale. This can violate language/locale policy because the skill implicitly enforces a specific language for outputs and interaction.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified with a lower bound only, which allows builds to resolve to different versions over time and makes the software supply chain non-reproducible. In a document-processing skill, this increases the chance of accidentally installing a vulnerable or breaking release of python-docx, especially given the library has had past XXE-related advisories.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
python-docx>=1.1.2
lxml>=5.3.0

Unverifiable Dependency: python-docx has 2 known advisory(ies) (CVE-2016-5851 (Improper Restriction of XML External Entity Reference in python-docx); CVE-2016-5851 (python-docx before 0.8.6 allows context-dependent attackers to conduct XML Exter)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

python-docx has known historical advisories, and because the manifest does not pin an exact version, there is no assurance that deployments will avoid affected releases. In a skill that creates and analyzes Office documents, XML parsing is part of the trust boundary, so uncertainty around the installed version is a legitimate security concern.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The lxml dependency is not pinned to an exact version, so installations may pull different releases depending on when and where the skill is deployed. Because lxml is a security-sensitive XML/HTML parsing library with a history of advisories, unpinned resolution materially increases supply-chain and exposure risk for this office-document processing skill.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
python-docx>=1.1.2
lxml>=5.3.0

Unverifiable Dependency: lxml has 14 known advisory(ies) (CVE-2021-43818 (lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through); CVE-2014-3146 (lxml Cross-site Scripting Via Control Characters); CVE-2021-28957 (lxml vulnerable to Cross-Site Scripting ) +11 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

lxml has multiple known advisories, and the current requirement does not make the installed version verifiable. Since this skill specializes in Office document handling and may process attacker-supplied document content, ambiguity around a parser dependency raises the risk of deploying a vulnerable parser in production.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.