T09 · Insecure Skill Coding Practices
- Location
scripts/doc_to_docx_com.py:26- Finding
Microsoft Word Automation Opens Untrusted Documents Without Explicitly Disabling Macros
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it claims, but its Word conversion path opens legacy documents through Microsoft Word without disabling macros or warning users about active-content risk.
Review before installing. Only use the Word conversion path on documents you trust, or run it in an isolated Windows account or VM; the script should be hardened to disable Office macros and active content before opening files. Use a virtual environment with pinned dependency versions for the Python packages.
scripts/doc_to_docx_com.py:26Microsoft Word Automation Opens Untrusted Documents Without Explicitly Disabling Macros
SKILL.md:44Third-Party Python Dependencies Are Installed Without Version or Integrity Pinning
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The description claims the skill converts both legacy Word and Excel files (.doc/.xls to .docx/.xlsx). However, the provided code implements only .doc to .docx conversion through Word COM automation. There is no Excel-related logic, no use of Python spreadsheet libraries, and no .xls/.xlsx handling. The implemented behavior is aligned with part of the description, but the overall declared purpose is materially broader than the actual code chunk.
The code chunk is narrowly focused on converting .xls spreadsheets to .xlsx using xlrd and openpyxl. It supports batch conversion and some preservation of dates, booleans, errors, fonts, alignment, and number formats. However, the declared description presents the skill as covering both .doc and .xls legacy Office conversion. Since the supplied code contains no Word document conversion logic and no Windows/Word automation, the actual behavior is materially narrower than the declared purpose. This is a description-behavior mismatch.
This markdown file contains user-facing natural language only in Chinese, from the title through the conclusions. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation unless the regional constraint is documented and justified, which is not stated here.
The trigger "Office format migration" is broad and not limited to the specific .doc/.xls to .docx/.xlsx conversion behavior described by the skill. It could overlap with unrelated Office conversion or migration requests and may cause unintended invocation without clearer scope constraints.
No suspicious patterns detected.