Back to skill

Security audit

Dochub

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent document-knowledge-base purpose, but it asks for broad local file moves, runtime Python installation/execution, and sandbox bypass guidance that require user review.

Install only if you are comfortable giving the skill control over a dedicated document folder. Do not run it on a broad Documents, home, project, or synced folder; avoid disabling the sandbox; review a file move list before proceeding; and provision trusted, pinned Python dependencies yourself instead of allowing ad hoc installs.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:499
Finding

Sandbox Bypass Instruction Enables Unrestricted Filesystem Operations

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:499
Vulnerability Type: Sandbox bypass and privilege expansion
Risk Level: High

Source Snippet:

markdown
- On Windows, moving files into the Documents directory may trigger sandbox blocking and require `dangerouslyDisableSandbox`.

Technical Analysis

The Skill explicitly recommends disabling the execution sandbox when filesystem operations are blocked. A sandbox is a security boundary intended to constrain the Agent to approved files and directories. Disabling it grants substantially broader access than document conversion legitimately requires.

This instruction is particularly dangerous in combination with the initialization workflow, which relocates files recursively from a user-selected directory. The Skill does not require canonical path validation, a narrowly scoped permission grant, or verification that the selected directory is dedicated exclusively to the knowledge base.

Attack Path

  1. A user invokes initialization or update against a directory under the Windows Documents hierarchy.
  2. The Skill attempts to move source files into the raw/ directory.
  3. The sandbox blocks access outside the permitted workspace.
  4. Following the Skill instructions, the Agent reruns the operation with dangerouslyDisableSandbox.
  5. The Agent can then read, move, overwrite, or otherwise affect files beyond the original sandbox boundary.
  6. A mistaken path, malicious document workflow, or compromised dependency can abuse the expanded access to affect unrelated user data.

Impact Assessment

Exploitation can provide the Agent or code running through it with access to files outside the approved workspace. The effective scope is determined by the operating-system privileges of the Agent process and may include the user's Documents directory and other user-accessible locations.

Potential consequences include unauthorized file disclosure, relocatio ...[truncated 222 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove every instruction recommending dangerouslyDisableSandbox or equivalent sandbox bypasses.
  • Require the knowledge-base root to reside inside an explicitly approved workspace.
  • Resolve and canonicalize every path before use, then verify that it remains below the approved root.
  • Request narrowly scoped access to the specific source and destination directories rather than disabling the entire sandbox.
  • Stop safely and explain the required permission if an operation is blocked.
  • Add protection against symlink, junction, and path-traversal escapes.
  • Generate a reviewed file-operation manifest before moving data.
  • Implement rollback or recovery support for partially completed file operations.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:70
Finding

Overly Broad File Relocation Can Modify Unrelated User Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:70-74
Vulnerability Type: Excessive filesystem access and destructive file relocation
Risk Level: High

Source Snippet:

markdown
#### [2/7] Move original documents into raw/
- Move all files under KNOWLEDGE_BASE_ROOT into `raw/`, except existing `raw/`, `wiki/`, `update/`, and `_schema.md`.
- Preserve the original directory structure and organize files by their existing category subdirectories.
- Exclude temporary directories such as `.fnsync_temp_dir`.
- Move non-.docx and non-.xlsx files as well; they will be handled in step 4.

Technical Analysis

The initialization procedure moves nearly every file beneath a user-selected root, including unsupported and potentially unrelated files. This exceeds the minimum access needed to convert .docx and .xlsx documents.

The privacy confirmation required by the Skill only asks whether documents have been sanitized. It does not present an exact source-to-destination manifest or obtain informed approval for every affected file. The exclusions are also narrow and do not protect unrelated configuration, application, archive, media, or hidden files.

Because the root may be inferred from the current working directory, an incorrect or overly broad root can cause large-scale relocation. Renaming performed later in the workflow can further interfere with references to the original paths.

Attack Path

  1. A user selects, or the Agent infers, a broad directory as KNOWLEDGE_BASE_ROOT.
  2. The directory contains both intended office documents and unrelated files.
  3. Initialization recursively enumerates files while excluding only a short list of Skill-managed paths.
  4. All remaining files, including unsupported formats, are moved into raw/.
  5. Existing applications, shortcuts, scripts, or user workflows lose access to files at their original paths.
  6. Relocated files may subsequently be renamed, indexe ...[truncated 671 chars]
Remediation
View remediation

Remediation Suggestions

  • Restrict automatic processing to explicitly supported .docx and .xlsx files.
  • Do not relocate unsupported or unrelated files merely to index them.
  • Use copy-by-default behavior and preserve the original source files and paths.
  • Require an explicitly selected, dedicated knowledge-base directory; do not infer a broad root without confirmation.
  • Display a complete source-to-destination manifest and obtain explicit approval before any move.
  • Detect destination collisions and require a safe resolution before continuing.
  • Exclude hidden files, configuration files, executable content, symbolic links, and filesystem junctions unless individually approved.
  • Use transactional file operations with rollback and an operation journal.
  • Validate resolved paths before every read, write, rename, or move.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:435
Finding

Unpinned Runtime Package Installation Creates Supply-Chain Exposure

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:435-443
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Source Snippet:

bash
# Required dependencies
pip install python-docx openpyxl

# Optional fallback dependency
pip install "markitdown[all]"

The same unpinned required-package installation is also prescribed at SKILL.md:104.

Technical Analysis

The Skill directs the Agent to install dependencies from the configured Python package index at runtime without version constraints, cryptographic hashes, a lockfile, or index restrictions. Consequently, the code installed during one execution may differ from the code that was reviewed.

The markitdown[all] fallback further expands the dependency graph through optional extras, increasing the number of packages that must be trusted. Python package installation and import can execute package-controlled code with the permissions of the Agent process.

The audit found no evidence that the named packages are themselves malicious. The vulnerability is the unsafe, mutable dependency-resolution process rather than a confirmed malicious package.

Attack Path

  1. The Agent attempts document conversion and determines that a required library is unavailable.
  2. It follows the Skill instructions and invokes pip install without pinned versions or hashes.
  3. The package manager resolves the latest versions and transitive dependencies from its configured index.
  4. A compromised release, compromised index, dependency-confusion candidate, or newly vulnerable transitive package is installed.
  5. Package installation or later import executes attacker-controlled code with the Agent's permissions.
  6. The malicious code can access documents, generated knowledge-base files, credentials available to the process, and any filesystem locations exposed through sandbox bypass.

Impact Assessment

A compromised dependency ca ...[truncated 414 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin every direct and transitive dependency to a reviewed version.
  • Maintain a lockfile containing cryptographic hashes and install with hash verification.
  • Use a dedicated, isolated virtual environment with minimum filesystem permissions.
  • Install dependencies during a controlled deployment phase rather than dynamically during document processing.
  • Use an approved package index and disable untrusted supplemental indexes.
  • Avoid broad optional extras such as [all]; install only the specific features required.
  • Generate and review a software bill of materials.
  • Perform dependency vulnerability and provenance checks before release.
  • Fail safely and ask the user to provision dependencies when the verified environment is unavailable.

T07 · Tool Hijacking and Spoofing

Warning
Location
SKILL.md:103
Finding

Forced User-Specific Interpreter Path Permits Local Tool Substitution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:103
Vulnerability Type: Unverified hard-coded interpreter selection
Risk Level: Medium

Source Snippet:

markdown
**Python path:** Always use `C:/Users/skya2/.workbuddy/binaries/python/envs/default/Scripts/python.exe`
If dependencies must be installed: `pip install python-docx openpyxl`

The same hard-coded interpreter path is repeated at SKILL.md:446.

Technical Analysis

The Skill mandates an absolute Python executable belonging to a specific user and environment. It does not verify the executable's ownership, integrity, signature, permissions, or provenance before invoking it.

If the prescribed path is writable or can be prepared by another local principal, an attacker can place a malicious executable at that location. Calls that appear to perform ordinary document conversion would then execute attacker-controlled logic. The fixed path also bypasses the project's active trusted environment and makes deployment behavior dependent on an external local installation that is not part of the audited artifact.

The project does not itself create or replace this executable. Exploitation therefore requires prior local ability to control the specified path or its contents.

Attack Path

  1. An attacker obtains write access to the prescribed interpreter path, one of its parent directories, or the referenced virtual environment.
  2. The attacker replaces python.exe or modifies imported environment components with malicious content.
  3. A user invokes document initialization or update.
  4. The Agent follows the mandatory path instruction and launches the substituted interpreter.
  5. The malicious interpreter executes with the permissions of the Agent process while appearing to be a legitimate conversion operation.
  6. It can access the documents and output directories supplied to the conversion workflow.

Impact Assessment

Successful exploitatio ...[truncated 401 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the user-specific absolute interpreter requirement.
  • Use a project-owned, isolated virtual environment created through a documented and reproducible process.
  • Resolve the interpreter from trusted configuration rather than an arbitrary fixed user path.
  • Verify the resolved executable's canonical path, ownership, permissions, and integrity before execution.
  • Refuse interpreters located in directories writable by untrusted users.
  • Pin and verify the environment's dependencies.
  • Record the interpreter version and digest in audit logs.
  • Keep conversion inside the sandbox with access limited to the approved input and output directories.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill claims the raw layer is immutable and read-only, but the workflow later instructs moving files into raw/ and renaming them during normalization. This contradiction weakens safety guarantees: agents or users may trust raw/ as a preserved evidence source even though provenance and original filenames can be altered, which is especially risky for auditability and regulated document handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

L004 的描述整体以中文规定技能行为,且文档后续交互提示、输出模板与用户问答约定也全部固定为中文,没有说明可根据用户偏好切换语言。按照语言/locale 政策,若未提供选择或显式用户同意,这种默认强制单一语言属于自然语言策略风险。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs the agent to install dependencies and execute temporary Python scripts from a fixed interpreter path in order to process user-supplied documents. That expands the skill from document management into code execution and environment modification, increasing the attack surface and creating opportunities for abuse through hostile files, unsafe script generation, or unauthorized package installation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The update trigger includes broad phrases such as '有新文档', which can match ordinary conversation rather than an explicit request to run a file-management workflow. Because update performs scanning, conversion, reclassification, and file moves, accidental invocation could cause unintended processing or modification of user documents.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The search trigger uses generic phrases like '查一下' or '搜索', which overlap with normal assistant behavior and can invoke the skill when the user did not intend document-repository access. In this skill context, accidental activation may expose or traverse local knowledge-base contents without a sufficiently explicit user request.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The lint trigger includes broad terms like '知识库检查' and '健康检查', which may collide with ordinary requests about document quality or general review. While less dangerous than init/update, accidental lint can still read large amounts of repository content and generate persistent output files and logs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file contains all user-facing instructions in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

该参考文档全文以中文撰写,并在标题与正文中默认采用单一语言表达,但未说明这是面向特定中文用户群体的区域性/合规性限制,也未提供语言选择或 opt-in。根据规则,强制特定语言而无用户选择可能构成自然语言层面的语言/locale 政策问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.