Batch Processor Zh

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This instruction-only skill is coherent for user-requested bulk document processing, but users should verify the external office-mcp tool and use scoped folders or backups for sensitive files.

Before installing, make sure the office-mcp tool you use is trusted and configured safely. Run batch jobs only on clearly chosen folders, set a separate output directory when possible, and keep backups for HR, finance, legal, or other sensitive documents.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

A user could accidentally process the wrong folder or overwrite/rename many documents if the batch request is not scoped carefully.

Why it was flagged

The skill is intended to operate on many files in a folder, so an incorrect path or unclear output choice could cause large-scale unwanted conversions or file changes.

Skill content
"把这个文件夹里的100份PDF合同全部转成Word文档"
Recommendation

Use explicit input and output folders, test on a small sample first, and keep backups for important documents.

What this means

The reviewed skill text is simple, but the actual behavior depends on the user’s installed office-mcp implementation.

Why it was flagged

The skill depends on an external MCP tool, but the provided artifacts contain no install spec, source, version, or provenance for that tool.

Skill content
Tools Required
- office-mcp:batch_convert
Recommendation

Only use this skill with a trusted, reviewed office-mcp server/tool and confirm what permissions and file access it has.

What this means

Sensitive document contents may be exposed to whatever office-mcp tool is configured in the user’s environment.

Why it was flagged

The skill may pass selected business documents, invoices, or contracts to the referenced MCP tool, but the artifact does not define whether that tool is local, remote, or how it handles document contents.

Skill content
支持PDF转Word、Excel转换、发票提取、合同分析等多类型文件并行处理
Recommendation

Avoid processing confidential files unless you understand and trust the configured MCP tool’s data handling, storage, and network behavior.