Back to skill

Security audit

Doc Xls2docx Xlsx

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but its Word conversion path opens legacy documents through Microsoft Word without disabling macros or warning users about active-content risk.

Review before installing. Only use the Word conversion path on documents you trust, or run it in an isolated Windows account or VM; the script should be hardened to disable Office macros and active content before opening files. Use a virtual environment with pinned dependency versions for the Python packages.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/doc_to_docx_com.py:26
Finding

Microsoft Word Automation Opens Untrusted Documents Without Explicitly Disabling Macros

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:44
Finding

Third-Party Python Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
\ --hash=sha256: openpyxl== \ --hash=sha256: ``` Install it in an isolated virtual environment with hash enforcement: ```bash python -m venv .venv python -m pip install --require-hashes -r requirements.txt ``` Additional controls should include: 1. Pin all direct and transitive dependencies to reviewed versions. 2. Generate hashes from trusted, verified artifacts. 3. Configure an approved package index explicitly where organizational controls require it. 4. Scan locked dependencies for known vulnerabilities and update them through a controlled review process. 5. Avoid installing dependencies with administrator privileges or into a shared system Python environment. 6. Commit the lock file to the project so installations remain reproducible. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description claims the skill converts both legacy Word and Excel files (.doc/.xls to .docx/.xlsx). However, the provided code implements only .doc to .docx conversion through Word COM automation. There is no Excel-related logic, no use of Python spreadsheet libraries, and no .xls/.xlsx handling. The implemented behavior is aligned with part of the description, but the overall declared purpose is materially broader than the actual code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code chunk is narrowly focused on converting .xls spreadsheets to .xlsx using xlrd and openpyxl. It supports batch conversion and some preservation of dates, booleans, errors, fonts, alignment, and number formats. However, the declared description presents the skill as covering both .doc and .xls legacy Office conversion. Since the supplied code contains no Word document conversion logic and no Windows/Word automation, the actual behavior is materially narrower than the declared purpose. This is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing natural language only in Chinese, from the title through the conclusions. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation unless the regional constraint is documented and justified, which is not stated here.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger "Office format migration" is broad and not limited to the specific .doc/.xls to .docx/.xlsx conversion behavior described by the skill. It could overlap with unrelated Office conversion or migration requests and may cause unintended invocation without clearer scope constraints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.