Back to skill

Security audit

word-document-organizer

Security checks for vulnerabilities and agentic risk

Overview

This Word-formatting skill is mostly purpose-aligned, but its runtime instructions expose users to unintended code execution, silent package installation, and in-place document overwrites.

Install only if you are comfortable running local shell and Python document-modification steps. Use it on copies of documents, specify an explicit output_path, avoid legacy .doc files, and do not pass document paths or options from untrusted sources unless the skill is fixed to pass parameters safely and avoid automatic unpinned pip installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:102
Finding

Arbitrary Python Code Injection Through Unescaped Parameter Interpolation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:84
Finding

Automatic Installation of an Unpinned Third-Party Dependency

Content
View full analysis
/dev/null || pip3 install python-docx -q ``` ### Technical Analysis When the `docx` module is unavailable, the skill automatically invokes `pip3` to retrieve and install the latest available release of `python-docx`. The command does not specify an exact version, verify a package hash, use a reviewed lock file, or constrain the package repository to a trusted configuration. As a result, the installed artifact can change after the skill has been audited. The effective dependency source can also be influenced by local pip configuration, environment variables, configured package indexes, or a compromised upstream distribution channel. Package installation may execute package build or installation logic. The command therefore creates a supply-chain execution path outside the reviewed project content. It also conflicts with the skill's statement that network access is unnecessary because installation normally requires access to a package index when the dependency is absent. ### Attack Path 1. The environment does not already provide an importable `docx` module. 2. The import check fails and triggers `pip3 install python-docx -q`. 3. Pip resolves the package using its active index and configuration without enforcing a reviewed version and hash. 4. A compromised release, package repository, dependency, or attacker-controlled package source supplies malicious installation content. 5. Pip installs or executes that content with the permissions of the user running the skill. 6. Malicious package behavior can then affect the document-processing run and resources accessible to that user. This path depends on compromise or manipulation of the dependency source or package-resolution configuration; the audited file does not itself contain a malicious packa ...[truncated 418 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

L004 将技能描述为面向中文文档整理,而后续模板在 L046-L049、L121-L140 中默认施加宋体、黑体、微软雅黑等特定中文字体/版式规则,但文档没有要求用户确认语言或 locale 适配性。对于非中文或混合语言文档,这种默认强制区域设置属于语言/locale 约束,且未提供显式 opt-in 或选择流程。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

L017-L022 列出的“格式化文档”“排版优化”“规范文档格式”等触发语缺少对 Word 或 .docx 场景的明确限定,容易与普通写作、排版或其他文档编辑请求混淆。该技能虽然有标题和参数说明,但触发条件部分本身未提供负例或排除条件,仍可能造成非目标场景下的意外激活。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documentation says the required input supports only .docx, but the bash validation explicitly accepts both .docx and .doc while the Python code uses python-docx, which does not reliably process legacy .doc files. This mismatch can cause failed runs, misleading behavior, and possible overwrite/backup confusion when users believe an unsupported file type is safely handled.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The security note claims failures will not damage the original file because processing happens before save, but the script defaults output_path to the original document path and overwrites it on success. Although a backup is created, this still contradicts the safety claim and increases the risk of accidental data loss or irreversible formatting changes if users do not notice the overwrite behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.generated_source_template_injection

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
SKILL.md:102