Back to skill

Security audit

Data To Word Report

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to generate Word reports from user-provided data without hidden persistence, credential access, or network execution.

Installers should understand that the skill may read uploaded datasets and save a Word document containing derived content. Use a normal isolated Python environment, install `python-docx` from a trusted source, and choose an output path where overwriting an existing file is acceptable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
scripts/gen_report.py:12
Finding

Unpinned Third-Party Dependency Installation Guidance

Content
View full analysis

Vulnerability Details

File Location: scripts/gen_report.py, lines 12-16
Vulnerability Type: Unpinned third-party dependency and supply-chain risk
Risk Level: Low

Vulnerable Code

python
except ImportError:
    print("Missing python-docx, please run: pip install python-docx")
    sys.exit(1)

Technical Analysis

When python-docx is unavailable, the script recommends installing it directly by package name without specifying a reviewed version, cryptographic hashes, a lockfile, or a trusted package index. This causes the resolved package and its transitive dependencies to depend on mutable package-repository state at installation time.

The script does not install the dependency automatically, so exploitation requires a user or automation process to follow the displayed command. If the package source, package release, dependency resolution process, or configured Python package index is compromised, attacker-controlled installation or import-time code could execute.

Attack Path

  1. The report generator runs in an environment where python-docx is absent.
  2. The import raises ImportError, and the script displays pip install python-docx.
  3. A user or automated setup process executes the suggested command.
  4. pip resolves a mutable, unpinned package version from its configured index.
  5. A compromised package release, dependency, or package index supplies attacker-controlled code.
  6. Malicious code executes during installation or when the report script subsequently imports the dependency.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the account performing the installation or running the report generator. This could expose data accessible to that account, modify files in its permission scope, tamper with generated reports, or compromise the associated Python environment. The code does not itself provide privilege escalation; elevated impact would occur only if installat ...[truncated 57 chars]

Remediation
View remediation

Remediation Suggestions

  1. Declare python-docx in a committed dependency manifest and pin it to a reviewed version.
  2. Generate and verify cryptographic hashes for all direct and transitive dependencies, then install with a command such as:
    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  3. Use an approved package index or an internally controlled dependency mirror rather than relying on unspecified environment configuration.
  4. Add automated dependency vulnerability and integrity scanning to the release process.
  5. Replace the generic installation prompt with instructions that reference the project's reviewed dependency manifest.
  6. Install and run the skill in an isolated virtual environment under a non-privileged account.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code is a document renderer, not an analysis generator. It accepts an output path and a JSON string describing report title, sections, paragraphs, and tables, then formats and saves a .docx file. There is no logic to read user-provided data files, derive key metrics, perform statistical or trend analysis, or generate findings/conclusions from raw data. The declared description overstates the skill’s analytical capabilities; the actual code only turns already-prepared content into a Word report.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The suggested triggers "generate analysis report," "convert data to Word," and especially "produce a report" are generic phrases that could match many ordinary requests outside this specific skill. The file does not provide tighter scope, constraints, or negative examples to clarify when this skill should or should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill processes uploaded data files and writes an output document to disk, but it does not clearly warn users about those data-handling side effects. This can create unintended disclosure or privacy risk, especially if users provide sensitive datasets without realizing the files will be read and persisted as a report artifact.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script repeatedly forces output text to use "Microsoft YaHei" and sets East Asia font properties, which imposes a specific locale/language presentation choice in generated reports. There is no user option or documentation indicating that the report format is intentionally region-specific, so this can conflict with language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.