T09 · Insecure Skill Coding Practices
- Location
SKILL.md:102- Finding
Arbitrary Python Code Injection Through Unescaped Parameter Interpolation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Word-formatting skill is mostly purpose-aligned, but its runtime instructions expose users to unintended code execution, silent package installation, and in-place document overwrites.
Install only if you are comfortable running local shell and Python document-modification steps. Use it on copies of documents, specify an explicit output_path, avoid legacy .doc files, and do not pass document paths or options from untrusted sources unless the skill is fixed to pass parameters safely and avoid automatic unpinned pip installs.
SKILL.md:102Arbitrary Python Code Injection Through Unescaped Parameter Interpolation
SKILL.md:84Automatic Installation of an Unpinned Third-Party Dependency
L004 将技能描述为面向中文文档整理,而后续模板在 L046-L049、L121-L140 中默认施加宋体、黑体、微软雅黑等特定中文字体/版式规则,但文档没有要求用户确认语言或 locale 适配性。对于非中文或混合语言文档,这种默认强制区域设置属于语言/locale 约束,且未提供显式 opt-in 或选择流程。
L017-L022 列出的“格式化文档”“排版优化”“规范文档格式”等触发语缺少对 Word 或 .docx 场景的明确限定,容易与普通写作、排版或其他文档编辑请求混淆。该技能虽然有标题和参数说明,但触发条件部分本身未提供负例或排除条件,仍可能造成非目标场景下的意外激活。
The skill documentation says the required input supports only .docx, but the bash validation explicitly accepts both .docx and .doc while the Python code uses python-docx, which does not reliably process legacy .doc files. This mismatch can cause failed runs, misleading behavior, and possible overwrite/backup confusion when users believe an unsupported file type is safely handled.
The security note claims failures will not damage the original file because processing happens before save, but the script defaults output_path to the original document path and overwrites it on success. Although a backup is created, this still contradicts the safety claim and increases the risk of accidental data loss or irreversible formatting changes if users do not notice the overwrite behavior.
Detected: suspicious.generated_source_template_injection