Back to skill

Security audit

gongwen_format

Security checks for vulnerabilities and agentic risk

Overview

This is a focused Chinese official-document formatting skill with no evidence of hidden data access, persistence, privilege escalation, or automatic unsafe behavior.

Install this only if you need Chinese GB/T 9704-style official document formatting. Prefer using a pinned docx dependency and a lockfile before running the JavaScript template, and be aware that the broad triggers may activate for ordinary writing or report requests.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
gongwen_template.js:7
Finding

Unpinned Third-Party npm Dependency

Content
View full analysis

Vulnerability Details

File Location: gongwen_template.js:7
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Low

javascript
/**
 * gongwen_template.js - 公文模板 for docx-js
 *
 * 基于 GB/T 9704-2012 和企业内部公文格式要求
 *
 * 使用方法:
 *   1. npm install docx
 *   2. node gongwen_template.js
 */

Technical Analysis

The usage instructions direct users to install the docx package without specifying an exact version. The project also contains no reviewed package.json or committed lockfile that would constrain the package and its transitive dependencies to known versions.

Running npm install docx resolves mutable content from the configured npm registry. Package installation can execute npm lifecycle scripts unless scripts are explicitly disabled. Consequently, a future compromised package release, compromised transitive dependency, registry substitution, or malicious registry configuration could cause code not reviewed as part of this project to execute during installation.

This finding concerns supply-chain integrity rather than confirmed malicious behavior in the current docx package. The installation command is documentation and is not automatically executed by the Skill.

Attack Path

  1. An attacker compromises a future release of docx, one of its transitive dependencies, or the package registry used by the victim.
  2. The attacker adds malicious code or an installation lifecycle script to the resolved package content.
  3. A user follows the documented npm install docx command.
  4. npm retrieves the mutable package version and dependency graph selected at installation time.
  5. Malicious package code or a lifecycle script executes with the privileges of the user running npm.
  6. Depending on those privileges, the payload could access files available to that user, alter project content, obtain environment variables, or establish network communication.

...[truncated 631 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add a reviewed package.json that pins docx to an exact version rather than using a floating version range.
  2. Generate, review, and commit a package-lock.json so direct and transitive dependency versions and integrity hashes are reproducible.
  3. Replace the documented installation workflow with npm ci, which installs from the committed lockfile.
  4. Use npm ci --ignore-scripts when the selected dependency graph does not require lifecycle scripts.
  5. Review dependency provenance, maintainers, release history, lifecycle scripts, and transitive dependencies before updating.
  6. Run dependency installation as an unprivileged user in an isolated development environment or container.
  7. Apply automated dependency and lockfile scanning, and require review for dependency updates.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
81% confidence
Finding

The trigger phrase 'write gongwen' overlaps with a common built-in 'write' intent, creating a shadow-command condition where this skill may be selected when the user only intends a generic writing task. That can misroute requests, cause unintended formal document generation, and increase the chance of policy or workflow bypass through trigger confusion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes broad phrases such as 'create official document' and '工作报告', which can overlap with ordinary writing or reporting requests and cause the skill to activate outside its intended scope. In an agent setting, ambiguous invocation can lead to inappropriate template-driven output, override more suitable skills, or steer users into generating formal-looking documents they did not request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing content exclusively in Chinese, including headings, findings, and usage guidance. The provided policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The natural-language description specifies creating Chinese official documents and standardizing on Chinese national formatting conventions, but it does not indicate user choice or opt-in for language/locale. Under the stated policy, forcing a specific language or locale without user opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
87% confidence
Finding

The trigger '发文' is extremely short and context-ambiguous, so it may match many unrelated user inputs and invoke the skill unintentionally. Short triggers increase accidental activation risk and can degrade command routing reliability across the agent ecosystem.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all instructions and formatting guidance exclusively in Chinese, and nowhere indicates that the user can choose another language or that the skill is intentionally limited to Chinese-language users. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.