Back to skill

Security audit

Automation Master

Security checks for vulnerabilities and agentic risk

Overview

This office automation skill mostly matches its stated purpose, but it uses broad local execution and file-handling powers that need review before installation.

Review this skill before installing. Use it only in an isolated, non-admin Windows environment with dedicated temporary and output directories, restrict the LibreOffice executable path to a trusted administrator-managed binary, pin and review dependencies, disable or remove printing unless explicitly needed, and avoid processing confidential invoices or identity documents until logging and cleanup are fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
execute.py:557
Finding

Attacker-Controlled Executable Path Enables Arbitrary Code Execution

Content
View full analysis

Vulnerability Details

File Location: execute.py:557-563; execution sink at services/file_convert_service.py:82-96
Vulnerability Type: Untrusted executable selection
Risk Level: Critical

Code Snippet

python
convert_tool = params.get(
    'libreoffice_path',
    r"D:\Program Files\libreoffice\program\soffice.exe"
)
success = MutualConver._convert_with_libreoffice_fast(
    pdf_info['path'], docx_path, convert_tool, 'docx'
)
python
cmd = [
    convert_tool,
    "--headless",
    "--convert-to", output_format,
    "--outdir", output_dir,
    input_path
]

process = subprocess.Popen(
    cmd,
    stdout=subprocess.PIPE,
    stderr=subprocess.PIPE,
    creationflags=subprocess.CREATE_NO_WINDOW
)

Technical Analysis

The libreoffice_path request parameter is accepted without an allowlist, canonical-path validation, trusted-directory restriction, or executable identity verification. It is then used as the first argument to subprocess.Popen.

Using an argument array prevents shell metacharacter injection, but it does not prevent execution of an attacker-selected local program. If an attacker can reference an existing executable or place an executable in a location accessible to the service, the program will run with the privileges of the Skill process.

Attack Path

  1. The attacker places or identifies a malicious executable accessible to the service account.
  2. The attacker invokes invoice_extract with at least one PDF file.
  3. The attacker supplies the malicious executable path in libreoffice_path.
  4. handle_invoice_extract passes the path to _convert_with_libreoffice_fast.
  5. subprocess.Popen launches the attacker-selected executable.
  6. The executable runs with the Skill process's filesystem and operating-system permissions.

Impact Assessment

Successful exploitation permits arbitrary local code execution under the service ...[truncated 242 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove libreoffice_path from user-controlled request parameters.
  • Configure the executable path through an administrator-managed, read-only configuration.
  • Resolve and canonicalize the configured path before use.
  • Require the executable to reside in a trusted installation directory.
  • On Windows, verify the executable's Authenticode signature and expected publisher.
  • Reject executables located in upload, temporary, user-profile, or other writable directories.
  • Run conversion in an isolated, low-privilege worker with restricted filesystem access.

T09 · Insecure Skill Coding Practices

Error
Location
execute.py:257
Finding

Path Traversal Through Uploaded and Generated Filenames

Content
View full analysis

Vulnerability Details

File Location: execute.py:257-259, execute.py:346-349, execute.py:408-410, and execute.py:441-444
Vulnerability Type: Path traversal and arbitrary file overwrite
Risk Level: High

Code Snippet

python
src_path = file_info.get('path')
if src_path and os.path.exists(src_path):
    dst_path = os.path.join(input_dir, file_info.get('name'))
    shutil.copy2(src_path, dst_path)
    saved_files.append(dst_path)
python
src_path = file_info['path']
file_name = file_info['name']
dst_path = os.path.join(input_dir, file_name)
shutil.copy2(src_path, dst_path)
file_times[file_name] = os.path.getmtime(src_path)
python
src_path = file_info['path']
dst_path = os.path.join(temp_dir, file_info['name'])
shutil.copy2(src_path, dst_path)
python
save_name = params.get('save_name', 'merged_result')
output_path = os.path.join(output_dir, f"{save_name}.xlsx")
DataOperation.data_pd_write(
    output_path,
    params.get('save_sheet_name', 'Sheet1'),
    merged_df
)

Technical Analysis

Uploaded filenames and the merge result's save_name are incorporated into filesystem paths without rejecting absolute paths, parent-directory components, path separators, or Windows drive and UNC paths.

os.path.join does not establish a security boundary. A name containing parent-directory components can escape the intended temporary directory, and an absolute path can replace the intended base path on applicable platforms. The subsequent shutil.copy2 and spreadsheet-writing operations may create or overwrite files outside the temporary workspace.

Attack Path

  1. The attacker submits a file whose supplied name contains parent-directory traversal components or an absolute path.
  2. The application joins that name to input_dir or temp_dir without normalization and containment validation.
  3. The resulting path resolves outside the int ...[truncated 721 chars]
Remediation
View remediation

Remediation Suggestions

  • Generate internal filenames on the server rather than trusting client-supplied names.
  • Apply os.path.basename only as a secondary defense; explicitly reject path separators, absolute paths, drive prefixes, UNC paths, and .. components.
  • Canonicalize both the base directory and candidate path with realpath.
  • Enforce containment using os.path.commonpath before every read, copy, move, or write.
  • Restrict save_name to a conservative allowlist such as letters, numbers, spaces, underscores, and hyphens.
  • Use exclusive file creation where overwriting is not required.
  • Run the service with access only to dedicated temporary and output directories.

T09 · Insecure Skill Coding Practices

Error
Location
services/template_engine/executor.py:118
Finding

Untrusted DOCX Templates Are Rendered Without a Jinja Sandbox

Content
View full analysis

Vulnerability Details

File Location: services/template_engine/executor.py:118-121
Vulnerability Type: Server-side template injection
Risk Level: High

Code Snippet

python
context = self._build_smart_context(
    data,
    config.get('data_key', '')
)

tpl = DocxTemplate(file_path)
tpl.render(context)
tpl.save(file_path)

Technical Analysis

The generation feature accepts a user-supplied DOCX template and renders its Jinja-style expressions through docxtpl. No explicitly sandboxed environment, attribute-access policy, callable restriction, or template syntax allowlist is provided.

A malicious template can therefore attempt to traverse object attributes or invoke functionality exposed by the template engine. The exact primitives and final impact depend on the installed docxtpl and Jinja versions and on the objects exposed in the rendering context. At minimum, unrestricted evaluation creates a server-side template injection boundary and may permit information disclosure or resource exhaustion; vulnerable runtime combinations may permit arbitrary code execution.

Attack Path

  1. The attacker creates a DOCX template containing crafted Jinja expressions rather than ordinary placeholders.
  2. The attacker uploads the crafted template and a data workbook.
  3. The attacker invokes action=generate.
  4. DocxTemplate.render evaluates the expressions in the service process.
  5. The expressions attempt object traversal, access to unintended values, expensive computation, or execution primitives available through the installed template runtime.
  6. Any successful expression executes with the permissions and resource access of the Skill process.

Impact Assessment

Confirmed impact includes exposure to template-driven denial of service and unintended runtime data access. Depending on the concrete Jinja/docxtpl dependency versions and reachable objects, exploitation may escalate to arb ...[truncated 95 chars]

Remediation
View remediation

Remediation Suggestions

  • Render untrusted templates only through jinja2.sandbox.SandboxedEnvironment.
  • Prohibit attribute access, callable invocation, imports, filters, tests, and globals that are not strictly required.
  • Permit only simple variable substitution and narrowly defined loops.
  • Convert the rendering context into copied primitive values and plain dictionaries.
  • Parse and reject unsupported template nodes before rendering.
  • Set execution time, memory, file-size, row-count, and output-size limits.
  • Process templates in an isolated worker with no network access and minimal filesystem permissions.
  • Pin and continuously review the docxtpl and Jinja dependency versions.

T08 · Insecure Dependencies

Error
Location
requirements.txt:2
Finding

Incorrect and Unpinned Dependency Definitions Create Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:2-23, especially requirements.txt:19
Vulnerability Type: Incorrect package identity and unconstrained dependency resolution
Risk Level: High

Code Snippet

text
pandas>=1.5.0
numpy>=1.23.0
openpyxl>=3.0.0
python-docx>=0.8.11
docxtpl>=0.16.0
Pillow>=9.0.0
pypdf>=3.0.0
pdf2docx>=0.5.0
tabula-py>=2.0.0
fitz>=0.0.1
psutil>=5.8.0

Technical Analysis

The source imports fitz as the module provided by PyMuPDF, but the requirements file declares the distribution named fitz. The expected Python package distribution is PyMuPDF; declaring fitz can install an unrelated package.

In addition, all direct dependencies use open-ended lower bounds and no integrity hashes. Installation can therefore resolve materially different future versions without source review, making builds non-reproducible and increasing exposure to compromised, incompatible, or unexpectedly vulnerable releases.

Attack Path

  1. An administrator follows the project installation instructions and runs pip install -r requirements.txt.
  2. The package installer resolves the distribution named fitz, rather than the intended PyMuPDF distribution.
  3. It also selects arbitrary versions above each minimum constraint.
  4. Package installation and import-time code execute in the installation or application environment.
  5. A compromised, incorrect, or incompatible dependency can affect the host with the installer or service account's privileges.

Impact Assessment

The immediate effects include installation failure, wrong-package execution, unpredictable behavior, and non-reproducible deployments. If a resolved package or future release is malicious or compromised, it may execute arbitrary code during installation or import with the privileges used to install or run the Skill.

Remediation
View remediation

Remediation Suggestions

  • Replace the fitz distribution requirement with a reviewed, exact PyMuPDF version.
  • Pin every direct dependency to an exact version.
  • Generate a reviewed lock file that also fixes transitive dependency versions.
  • Require package hashes during installation.
  • Install only from an approved package index over authenticated TLS.
  • Run dependency vulnerability and provenance scanning in CI.
  • Rebuild and retest the lock file through a controlled update process.
  • Install dependencies in an isolated virtual environment using a non-administrative account.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
services/file_convert_service.py:34
Finding

Conversion Jobs Force-Terminate Unrelated LibreOffice Processes

Content
View full analysis

Vulnerability Details

File Location: services/file_convert_service.py:34-39; invoked at services/file_convert_service.py:64 and services/file_convert_service.py:142
Vulnerability Type: Overbroad process control
Risk Level: Medium

Code Snippet

python
@staticmethod
def kill_libreoffice():
    os.system('taskkill /f /im soffice.exe >nul 2>&1')
    os.system('taskkill /f /im soffice.bin >nul 2>&1')
    time.sleep(1)
python
MutualConver.kill_libreoffice()
time.sleep(2)
python
finally:
    MutualConver.kill_libreoffice()

Technical Analysis

Each conversion attempts to terminate every process named soffice.exe or soffice.bin on the host. The code does not verify process ownership, parent-child relationships, session identity, command-line arguments, or whether a process was created by the current conversion job.

This violates least privilege because the operation affects unrelated LibreOffice instances rather than only the child process launched for the conversion. The behavior is reachable through ordinary conversion requests.

Attack Path

  1. Another user or service has a LibreOffice process running, potentially with unsaved work.
  2. The attacker repeatedly invokes a conversion or invoice extraction operation.
  3. The conversion code runs taskkill before conversion.
  4. All matching LibreOffice processes that the service account is permitted to terminate are forcibly stopped.
  5. The same global termination is repeated during cleanup.

Impact Assessment

The attacker can disrupt concurrent document-processing jobs and interactive LibreOffice sessions. Unrelated users may lose unsaved data. If the service runs with elevated privileges, the termination scope can include processes belonging to additional users or services.

Remediation
View remediation

Remediation Suggestions

  • Remove image-name-wide taskkill calls.
  • Retain the Popen object and terminate only the child process created for the current job.
  • Track child process identifiers and validate ownership before termination.
  • Use a unique, isolated LibreOffice user profile for each worker or job.
  • Attempt graceful termination before forceful termination.
  • Execute conversions in isolated low-privilege worker processes.
  • Apply per-job timeouts and process-tree cleanup scoped to the worker.

T09 · Insecure Skill Coding Practices

Error
Location
execute.py:249
Finding

Sensitive Temporary Files Are Retained After Operations Complete

Content
View full analysis

Vulnerability Details

File Location: execute.py:249-250, execute.py:329-330, execute.py:341-342, execute.py:399, and execute.py:485-487
Vulnerability Type: Insecure temporary-file lifecycle
Risk Level: High

Code Snippet

python
input_dir = tempfile.mkdtemp(prefix='convert_input_')
output_dir = tempfile.mkdtemp(prefix='convert_output_')

try:
    saved_files = []
    for file_info in files:
        src_path = file_info.get('path')
        if src_path and os.path.exists(src_path):
            dst_path = os.path.join(input_dir, file_info.get('name'))
            shutil.copy2(src_path, dst_path)
            saved_files.append(dst_path)
finally:
    pass
python
work_dir = tempfile.mkdtemp(prefix='invoice_')
docx_dir = os.path.join(work_dir, 'docx_files')
output_dir = os.path.join(work_dir, 'output')
os.makedirs(docx_dir, exist_ok=True)
os.makedirs(output_dir, exist_ok=True)

Technical Analysis

The handlers create temporary directories for uploaded files, converted documents, generated files, invoices, and financial workbooks, but do not remove them after success or failure. The conversion handler explicitly contains an empty finally block.

The retained files can contain invoices, tax identifiers, financial records, HR data, templates, and generated documents. This also contradicts the documented statement that uploaded files are automatically cleaned after execution.

Attack Path

  1. A user processes sensitive office or financial documents.
  2. The application copies the documents into directories created with tempfile.mkdtemp.
  3. The operation returns or fails without deleting those directories.
  4. Files accumulate on the host for an indefinite period.
  5. Another local process, later host compromise, backup process, or administrator can recover the residual information.
  6. Repeated requests can also consume available disk space and degrade ...[truncated 366 chars]
Remediation
View remediation

Remediation Suggestions

  • Use tempfile.TemporaryDirectory as a context manager for all working directories.
  • Delete working inputs in a finally block on both success and failure.
  • Store downloadable outputs separately in a managed output service with a short enforced expiration period.
  • Apply restrictive filesystem permissions to temporary and result directories.
  • Do not reuse temporary directories between users or jobs.
  • Add scheduled cleanup as defense in depth for abandoned jobs, while retaining immediate per-job cleanup.
  • Monitor temporary-storage utilization and enforce per-request file-size and aggregate-space limits.
  • Update documentation so the stated retention behavior accurately matches the implemented lifecycle.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (86)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Subprocess lifecycle management, external process termination, and asynchronous cleanup tasks are materially more powerful than what is implied by a generic office automation description. If implemented broadly, these behaviors can kill unrelated software, lose unsaved work, or create hard-to-debug system instability, which makes the mismatch security-relevant rather than merely editorial.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

Subprocess lifecycle management, external process termination, and asynchronous cleanup tasks are materially more powerful than what is implied by a generic office automation description. If implemented broadly, these behaviors can kill unrelated software, lose unsaved work, or create hard-to-debug system instability, which makes the mismatch security-relevant rather than merely editorial.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Subprocess lifecycle management, external process termination, and asynchronous cleanup tasks are materially more powerful than what is implied by a generic office automation description. If implemented broadly, these behaviors can kill unrelated software, lose unsaved work, or create hard-to-debug system instability, which makes the mismatch security-relevant rather than merely editorial.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

Subprocess lifecycle management, external process termination, and asynchronous cleanup tasks are materially more powerful than what is implied by a generic office automation description. If implemented broadly, these behaviors can kill unrelated software, lose unsaved work, or create hard-to-debug system instability, which makes the mismatch security-relevant rather than merely editorial.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Subprocess lifecycle management, external process termination, and asynchronous cleanup tasks are materially more powerful than what is implied by a generic office automation description. If implemented broadly, these behaviors can kill unrelated software, lose unsaved work, or create hard-to-debug system instability, which makes the mismatch security-relevant rather than merely editorial.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Subprocess lifecycle management, external process termination, and asynchronous cleanup tasks are materially more powerful than what is implied by a generic office automation description. If implemented broadly, these behaviors can kill unrelated software, lose unsaved work, or create hard-to-debug system instability, which makes the mismatch security-relevant rather than merely editorial.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Subprocess lifecycle management, external process termination, and asynchronous cleanup tasks are materially more powerful than what is implied by a generic office automation description. If implemented broadly, these behaviors can kill unrelated software, lose unsaved work, or create hard-to-debug system instability, which makes the mismatch security-relevant rather than merely editorial.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Subprocess lifecycle management, external process termination, and asynchronous cleanup tasks are materially more powerful than what is implied by a generic office automation description. If implemented broadly, these behaviors can kill unrelated software, lose unsaved work, or create hard-to-debug system instability, which makes the mismatch security-relevant rather than merely editorial.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code can trigger actual printer output through AutoPrinter.judgment_print using user-controlled input_dir, sheet_name, area_print, and printer_name, causing real-world side effects. In an agent skill context, this is dangerous because it enables unauthorized physical actions, waste of paper/ink, disclosure of sensitive documents to shared printers, and potential harassment or operational disruption.

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
96% confidence
Finding

This uses os.system to execute a shell command that force-kills all soffice.exe processes on the host, not just a child process spawned by this service. Even though the command string is static and not directly command-injectable here, it grants unnecessary system-level control and can disrupt unrelated user sessions or other applications relying on LibreOffice.

Content

Scanner excerpt · services/file_convert_service.py (reported line 37)May include surrounding context.

python
@staticmethod
    def kill_libreoffice():
        """强制终止所有 LibreOffice 进程"""
        os.system('taskkill /f /im soffice.exe >nul 2>&1')
        os.system('taskkill /f /im soffice.bin >nul 2>&1')
        time.sleep(1)

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
96% confidence
Finding

This second os.system call force-kills all soffice.bin processes system-wide, expanding the blast radius beyond the current conversion task. In an office automation skill, this can cause denial of service, data loss in unrelated documents, and unsafe interference with other tenants or users on the machine.

Content

Scanner excerpt · services/file_convert_service.py (reported line 38)May include surrounding context.

python
def kill_libreoffice():
        """强制终止所有 LibreOffice 进程"""
        os.system('taskkill /f /im soffice.exe >nul 2>&1')
        os.system('taskkill /f /im soffice.bin >nul 2>&1')
        time.sleep(1) 
    
    @staticmethod

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file-repair workflow performs forceful termination of unrelated LibreOffice processes at the OS level, which is outside the minimally necessary scope for repairing a specific file. In context, this makes the skill more dangerous because office automation commonly runs on desktops or shared workers where unrelated office sessions may exist, creating a real risk of denial-of-service and data loss.

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
96% confidence
Finding

This shell call force-kills all running LibreOffice processes on the host, not just processes spawned by this service. That is a destructive system action that can terminate unrelated user sessions and cause data loss in unsaved documents; although the command string is constant and not shell-injected by user input here, it is still dangerous host-level behavior.

Content

Scanner excerpt · services/file_repair_service.py (reported line 20)May include surrounding context.

python
@staticmethod
    def kill_libreoffice():
        """强制终止所有 LibreOffice 进程"""
        os.system('taskkill /f /im soffice.exe >nul 2>&1')
        os.system('taskkill /f /im soffice.bin >nul 2>&1')
        time.sleep(2)

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
96% confidence
Finding

This second shell call repeats the same destructive pattern for soffice.bin, killing any matching process on the system regardless of ownership. In a multi-user or shared automation environment, this can disrupt unrelated work and make the service capable of broader denial-of-service than its stated file-repair purpose.

Content

Scanner excerpt · services/file_repair_service.py (reported line 21)May include surrounding context.

python
def kill_libreoffice():
        """强制终止所有 LibreOffice 进程"""
        os.system('taskkill /f /im soffice.exe >nul 2>&1')
        os.system('taskkill /f /im soffice.bin >nul 2>&1')
        time.sleep(2)
    
    # @staticmethod

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

This workflow executes external binaries and manages OS processes, meaning the skill can perform host-level actions beyond ordinary document handling. In the stated office-automation context, that is riskier because uploaded or selected files trigger code paths that invoke local executables, increasing the blast radius from file processing to arbitrary process execution and system disruption.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Numerous log statements record extracted invoice fields such as seller names, tax IDs, bank names, bank account numbers, invoice numbers, and other financial details in plain language. In a document-automation skill that processes potentially large volumes of financial records, this creates a scalable data leakage channel via application logs independent of the intended output files.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The service logs extracted personal identity data in plaintext, including passenger names and ID numbers. Logs are often broadly accessible to operators, shipped to centralized collectors, retained for long periods, and searched by many users, so exposing raw PII there materially increases breach impact and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file advertises batch file conversion, batch renaming, document generation, invoice extraction, and tax/financial reconciliation, all of which can affect user data, filenames, or sensitive financial records. The description contains no warning about data modification, reviewing outputs before applying changes, or handling sensitive documents, which fits the markdown-specific missing-user-warnings criterion.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises capabilities that imply file I/O and shell/process control, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens reviewability and sandbox enforcement because operators and users cannot easily see that the skill may read/write files and invoke Windows-specific subprocesses like taskkill or office automation helpers.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

L129-L137 将智能子集匹配描述为适用于“任何需要”在数据集中找对应记录的场景,并进一步强调“只要涉及”相关需求都可使用,但没有给出明确边界、限制条件或负面示例。对于 markdown 技能说明,这种宽泛表述会造成何时应调用该技能、何时不应调用的不明确。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invoice extraction feature processes sensitive financial and tax data such as invoice numbers, tax IDs, purchase details, and amounts, yet the documentation provides no meaningful warning about confidentiality, retention, sharing, or compliance obligations. In this context, missing privacy and data-handling guidance increases the chance of inappropriate use on highly sensitive documents and weakens informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

Batch renaming can irreversibly alter large numbers of user files, but the documentation does not prominently warn about the risk of accidental mass changes, collisions, or workflow breakage. Because the skill is positioned as a convenience automation tool, insufficient warning makes destructive mistakes more likely in normal use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing natural-language text in Chinese in the module header, and later user-facing messages throughout the file are also Chinese-only. Under the policy rule, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly justified or optional.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest describes file processing, data extraction, and intelligent data matching, but this code goes beyond ordinary in-process document handling by accepting a configurable executable path and invoking LibreOffice for conversion. Spawning or relying on an external program is a materially broader capability than the manifest communicates, especially because it introduces host-level execution dependency rather than just document processing logic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

User-facing docstrings, status messages, errors, and logs throughout the file are written exclusively in Chinese, indicating the skill is designed to communicate in a fixed language. There is no evidence of user opt-in, locale selection, or documented justification for restricting the skill to Chinese output.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.