Back to skill

Security audit

pandoc-docx

Security checks for vulnerabilities and agentic risk

Overview

This skill is a document converter as advertised, but some scripts can be tricked into running unintended commands or modifying files more broadly than users may expect.

Install only if you are comfortable reviewing or fixing the shell scripts first. Use copies of documents, avoid untrusted replacement text or conversion option values, do not run npm install for the declared tool dependencies, and install pandoc-related system packages through trusted OS package managers.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/doc-edit.sh:61
Finding

Arbitrary Command Execution Through GNU sed Expression Injection

Content
View full analysis

Vulnerability Details

File Location: scripts/doc-edit.sh:61-67
Vulnerability Type: Command injection through dynamically constructed sed expressions
Risk Level: High

Vulnerable Code

bash
      PATTERN="$1"
      REPLACEMENT="$2"
      TMPFILE=$(mktemp --suffix=.md)
      
      # Read, replace, and write back
      "$SCRIPT_DIR/doc-read.sh" "$FILE" markdown | sed "s/$PATTERN/$REPLACEMENT/g" > "$TMPFILE"
      "$SCRIPT_DIR/doc-write.sh" "$FILE" "$TMPFILE" markdown

Technical Analysis

Both PATTERN and REPLACEMENT are supplied by the caller and interpolated directly into a sed program. Shell quoting prevents a second round of shell expansion, but it does not make the values safe inside sed syntax.

An attacker can include sed delimiters, command separators, flags, backslashes, or newlines in these values. On GNU sed, the e substitution flag executes the resulting pattern space as a shell command. A crafted replacement can terminate the intended substitution, introduce the e flag, and comment out or otherwise neutralize the remaining generated syntax.

This is more severe than ordinary regular-expression injection because the generated sed program can cross the boundary from text manipulation into local command execution.

Attack Path

  1. The attacker influences the arguments supplied to the documented replace operation.
  2. The Agent invokes a command equivalent to:
    bash
    ./scripts/doc-edit.sh document.docx replace "target" "crafted sed payload"
    
  3. The script inserts the attacker-controlled values into:
    bash
    sed "s/$PATTERN/$REPLACEMENT/g"
    
  4. The crafted replacement closes the intended expression and introduces GNU sed's e execution flag.
  5. When a matching line is processed, sed passes the generated text to a shell.
  6. The injected command executes with the same operating-system privileges and environment as the Agent process ...[truncated 558 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not generate a sed program by directly interpolating untrusted values.
  • Implement literal replacement using a language API that separates data from executable replacement syntax.
  • If regular-expression replacement is an intentional feature, explicitly document it and safely escape:
    • The selected sed delimiter
    • Backslashes
    • Ampersands in replacement strings
    • Newlines and command separators
    • Any syntax capable of adding sed flags or commands
  • Do not permit GNU sed's e flag or attacker-controlled sed programs.
  • Pass pattern and replacement values through environment variables or another data-only channel to a dedicated replacement implementation.
  • Write the edited document to a separate temporary output and atomically replace the original only after every conversion succeeds.
  • Add cleanup traps for temporary files.
  • Add regression tests covering delimiters, semicolons, newlines, backslashes, ampersands, malformed regular expressions, and attempted e-flag injection.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/doc-convert.sh:17
Finding

Pandoc Option Injection Through Unquoted Argument Construction

Content
View full analysis

Vulnerability Details

File Location: scripts/doc-convert.sh:17-31 and scripts/doc-convert.sh:105
Vulnerability Type: Argument injection into an external command
Risk Level: High

Vulnerable Code

bash
      --extract-media)
          EXTRACT_MEDIA="--extract-media=$2"
          shift 2
          ;;
      --reference-doc)
          REFERENCE_DOC="--reference-doc=$2"
          shift 2
          ;;
      --wrap)
          WRAP_MODE="--wrap=$2"
          shift 2
          ;;
bash
# Execute conversion
pandoc "$INPUT" -o "$OUTPUT" $EXTRACT_MEDIA $REFERENCE_DOC $WRAP_MODE

Technical Analysis

The script constructs complete Pandoc options as strings and later expands those variables without quotes. Bash consequently performs word splitting and pathname expansion on their contents.

Although each variable is intended to represent one option, a caller can supply a value containing whitespace so that it becomes multiple command-line arguments. The additional words can be interpreted as independent Pandoc options rather than as part of the original media directory, reference document, or wrap-mode value.

Pandoc supports options that invoke external filters and otherwise alter conversion behavior. Injection of such an option can therefore exceed ordinary format manipulation and potentially execute an attacker-controlled filter. Quoting the variable expansions would prevent splitting, but a Bash array is the safer design for constructing command arguments.

Attack Path

  1. The attacker controls or influences a value passed to --extract-media, --reference-doc, or --wrap.
  2. The attacker places whitespace followed by an additional Pandoc option in that value.
  3. The parser stores the complete value in one shell variable without validation.
  4. At line 105, the variable is expanded without quotes.
  5. Bash splits the value into multiple arguments.
  6. Pandoc interp ...[truncated 620 chars]
Remediation
View remediation

Remediation Suggestions

  • Build the Pandoc command with a Bash array:
    bash
    args=("$INPUT" -o "$OUTPUT")
    
    if [ -n "$EXTRACT_MEDIA_VALUE" ]; then
        args+=("--extract-media=$EXTRACT_MEDIA_VALUE")
    fi
    
    if [ -n "$REFERENCE_DOC_VALUE" ]; then
        args+=("--reference-doc=$REFERENCE_DOC_VALUE")
    fi
    
    if [ -n "$WRAP_VALUE" ]; then
        args+=("--wrap=$WRAP_VALUE")
    fi
    
    pandoc "${args[@]}"
    
  • Store raw option values rather than preassembled command fragments.
  • Restrict wrap mode to the explicit allowlist preserve, auto, or none.
  • Reject control characters, embedded newlines, and invalid paths.
  • Verify that the reference document is a regular file with an approved format.
  • Verify that the media destination is within an authorized output directory when the Skill operates in a restricted workspace.
  • Use -- where supported to terminate option processing before positional file operands.
  • Add tests proving that whitespace, wildcard characters, and strings resembling Pandoc options remain part of a single argument.

T08 · Insecure Dependencies

Warning
Location
package.json:30
Finding

System Executables Incorrectly Declared as Broadly Versioned npm Dependencies

Content
View full analysis

Vulnerability Details

File Location: package.json:30-38
Vulnerability Type: Dependency confusion and unsafe dependency resolution
Risk Level: Medium

Vulnerable Code

json
"dependencies": {
  "pandoc": ">=2.0"
},
"optionalDependencies": {
  "libreoffice": ">=6.0",
  "poppler-utils": ">=0.8",
  "texlive": ">=2020"
}

Technical Analysis

The shell scripts require operating-system executables named pandoc, libreoffice, and pdftotext. The project documentation correctly instructs users to install these tools through apt or Homebrew.

However, package.json declares similarly named entries as npm dependencies. npm dependency declarations identify packages in an npm registry; they do not install or verify the corresponding operating-system executables. The open-ended minimum ranges also permit any later matching package version and no lockfile was identified during the audit.

Consequently, running npm installation can resolve unrelated third-party packages whose names resemble the required system tools. Such packages do not necessarily satisfy the runtime requirements, and npm package lifecycle scripts may execute during installation. The audit did not establish that the named registry packages are malicious; the confirmed issue is the unnecessary and misleading exposure to a separate dependency ecosystem.

Attack Path

  1. A user or automated build treats package.json as installation metadata and runs an npm installation command.
  2. npm resolves the names from the configured package registry using the broad version constraints.
  3. Registry packages unrelated to the required operating-system binaries may be downloaded.
  4. Any permitted package lifecycle scripts execute under the privileges of the user or build runner.
  5. The installation may still fail to provide the executables that the shell scripts locate through command -v.

Impact Assessment

The declarations cr ...[truncated 541 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove pandoc, libreoffice, poppler-utils, and texlive from npm dependency fields unless verified JavaScript libraries with those exact identities are genuinely required.
  • Keep the existing operating-system package installation guidance in the documentation.
  • Use scripts/check-deps.sh or a dedicated preflight check to verify the required executables and minimum versions.
  • If JavaScript dependencies are added later, verify package ownership and provenance, use bounded versions, commit a lockfile, and enable integrity and vulnerability checks.
  • Configure CI to install system packages explicitly through a trusted base image or operating-system package repository.
  • Avoid automatic installation logic that fetches replacement binaries from unverified sources.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (34)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents operations that create and edit .docx files, including writing output documents and editing existing documents. Although the capability is clear, there is no explicit user warning that these actions may overwrite or alter user data, which is the kind of behavior the README should disclose for markdown-scoped warning checks.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 24)May include surrounding context.

bash
# Install pandoc (required)
sudo apt install pandoc        # Linux
brew install pandoc            # macOS

# Optional: Install additional tools

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 28)May include surrounding context.

bash
# Install pandoc (required)
sudo apt install pandoc        # Linux
brew install pandoc            # macOS

# Optional: Install additional tools

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 29)May include surrounding context.

bash
# Install pandoc (required)
sudo apt install pandoc        # Linux
brew install pandoc            # macOS

# Optional: Install additional tools

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README includes direct examples for appending to and replacing text in an existing .docx file, which can affect user data and may be irreversible if run on the wrong file. The surrounding documentation does not provide a caution about in-place modification, backups, or verifying the target path before use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are broad enough that ordinary mentions of Word files, pandoc, or generic actions like '创建 Word' / '修改 docx' may activate the skill when the user did not clearly intend document conversion or modification. In an agent setting, unintended activation can lead to reading, rewriting, or converting local files, which creates a meaningful risk of accidental data exposure or destructive file operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The usage section describes commands that write, convert, and edit documents but does not prominently warn that these operations may overwrite, create, or alter files. In a skill intended for automated agent use, lack of an explicit warning increases the chance of unintended document modification and loss of user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The bulk conversion scenario encourages repeated file operations across many documents without a warning about scope, output location, overwrite behavior, or sensitive-content handling. In an automated environment, this can amplify mistakes from a single ambiguous request into widespread file modification or mass extraction of document contents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

All comments, usage instructions, and status/error messages are presented only in Chinese, with no indication that the skill is region-specific or that users can select another language. This creates a natural-language locale constraint without opt-in, which matches the policy-violation category for language or locale restrictions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script performs write-back operations in both the append and replace paths via doc-write.sh, which can alter the specified file in place. Although it prints a success message afterward, there is no prior confirmation prompt or explicit warning comment/docstring near the destructive action to disclose that the original document will be modified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script’s natural-language strings, including its description, usage text, and error messages, are written exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 130)May include surrounding context.

md
# Word .docx - 直接使用 pandoc
        if ! command -v pandoc &>/dev/null; then
            echo "❌ 需要安装 pandoc" >&2
            echo "安装:sudo apt install pandoc  或  brew install pandoc" >&2
            exit 1
        fi
        pandoc "$FILE" -t "$FORMAT"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 136)May include surrounding context.

md
# Word .docx - 直接使用 pandoc
        if ! command -v pandoc &>/dev/null; then
            echo "❌ 需要安装 pandoc" >&2
            echo "安装:sudo apt install pandoc  或  brew install pandoc" >&2
            exit 1
        fi
        pandoc "$FILE" -t "$FORMAT"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 137)May include surrounding context.

md
# Word .docx - 直接使用 pandoc
        if ! command -v pandoc &>/dev/null; then
            echo "❌ 需要安装 pandoc" >&2
            echo "安装:sudo apt install pandoc  或  brew install pandoc" >&2
            exit 1
        fi
        pandoc "$FILE" -t "$FORMAT"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 138)May include surrounding context.

md
# Word .docx - 直接使用 pandoc
        if ! command -v pandoc &>/dev/null; then
            echo "❌ 需要安装 pandoc" >&2
            echo "安装:sudo apt install pandoc  或  brew install pandoc" >&2
            exit 1
        fi
        pandoc "$FILE" -t "$FORMAT"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

md
# Word .docx - 直接使用 pandoc
        if ! command -v pandoc &>/dev/null; then
            echo "❌ 需要安装 pandoc" >&2
            echo "安装:sudo apt install pandoc  或  brew install pandoc" >&2
            exit 1
        fi
        pandoc "$FILE" -t "$FORMAT"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
# Word .docx - 直接使用 pandoc
        if ! command -v pandoc &>/dev/null; then
            echo "❌ 需要安装 pandoc" >&2
            echo "安装:sudo apt install pandoc  或  brew install pandoc" >&2
            exit 1
        fi
        pandoc "$FILE" -t "$FORMAT"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

md
# Word .docx - 直接使用 pandoc
        if ! command -v pandoc &>/dev/null; then
            echo "❌ 需要安装 pandoc" >&2
            echo "安装:sudo apt install pandoc  或  brew install pandoc" >&2
            exit 1
        fi
        pandoc "$FILE" -t "$FORMAT"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 171)May include surrounding context.

md
# Word .docx - 直接使用 pandoc
        if ! command -v pandoc &>/dev/null; then
            echo "❌ 需要安装 pandoc" >&2
            echo "安装:sudo apt install pandoc  或  brew install pandoc" >&2
            exit 1
        fi
        pandoc "$FILE" -t "$FORMAT"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/check-deps.sh (reported line 95)May include surrounding context.

sh
# Word .docx - 直接使用 pandoc
        if ! command -v pandoc &>/dev/null; then
            echo "❌ 需要安装 pandoc" >&2
            echo "安装:sudo apt install pandoc  或  brew install pandoc" >&2
            exit 1
        fi
        pandoc "$FILE" -t "$FORMAT"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/check-deps.sh (reported line 99)May include surrounding context.

sh
# Word .docx - 直接使用 pandoc
        if ! command -v pandoc &>/dev/null; then
            echo "❌ 需要安装 pandoc" >&2
            echo "安装:sudo apt install pandoc  或  brew install pandoc" >&2
            exit 1
        fi
        pandoc "$FILE" -t "$FORMAT"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/check-deps.sh (reported line 101)May include surrounding context.

sh
# Word .docx - 直接使用 pandoc
        if ! command -v pandoc &>/dev/null; then
            echo "❌ 需要安装 pandoc" >&2
            echo "安装:sudo apt install pandoc  或  brew install pandoc" >&2
            exit 1
        fi
        pandoc "$FILE" -t "$FORMAT"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/check-deps.sh (reported line 122)May include surrounding context.

sh
# Word .docx - 直接使用 pandoc
        if ! command -v pandoc &>/dev/null; then
            echo "❌ 需要安装 pandoc" >&2
            echo "安装:sudo apt install pandoc  或  brew install pandoc" >&2
            exit 1
        fi
        pandoc "$FILE" -t "$FORMAT"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/doc-convert.sh (reported line 78)May include surrounding context.

sh
# Word .docx - 直接使用 pandoc
        if ! command -v pandoc &>/dev/null; then
            echo "❌ 需要安装 pandoc" >&2
            echo "安装:sudo apt install pandoc  或  brew install pandoc" >&2
            exit 1
        fi
        pandoc "$FILE" -t "$FORMAT"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/doc-read.sh (reported line 40)May include surrounding context.

sh
# Word .docx - 直接使用 pandoc
        if ! command -v pandoc &>/dev/null; then
            echo "❌ 需要安装 pandoc" >&2
            echo "安装:sudo apt install pandoc  或  brew install pandoc" >&2
            exit 1
        fi
        pandoc "$FILE" -t "$FORMAT"

Static analysis

No suspicious patterns detected.