Back to skill

Security audit

Proposal Editor

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese-language professional document editing skill, with some ordinary document-integrity and dependency-hygiene cautions but no evidence of hidden, persistent, deceptive, or exfiltrating behavior.

Use this skill for Chinese professional proposal-style documents. Keep an original copy before editing, review generated DOCX output for formatting changes, and install `python-docx` only in a trusted virtual environment or from an approved pinned dependency source.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
workflows/main.md:149
Finding

Unpinned Runtime Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: workflows/main.md, line 149
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Complete Code Snippet:

markdown
- Prefer python-docx (`pip install python-docx`)

Technical Analysis

The workflow recommends installing python-docx without specifying an audited version, validating package hashes, using a lockfile, constraining the package index, or requiring an isolated environment. Consequently, the installed package and its transitive dependencies may vary between executions.

This creates a supply-chain exposure: if a selected release or one of its dependencies is compromised, the malicious package could execute code during installation or when imported for document processing. The project contains no evidence that python-docx itself is malicious; the issue is the unsafe and non-reproducible dependency installation instruction.

Attack Path

  1. A user invokes the skill to modify a Word document.
  2. The workflow recommends pip install python-docx.
  3. The command resolves the latest compatible package and dependencies from the configured Python package index without integrity verification.
  4. If the index, selected release, dependency, or local package-index configuration has been compromised, attacker-controlled code is installed.
  5. Malicious installation hooks or imported package code execute with the privileges of the user running the workflow.

Impact Assessment

Successful exploitation could allow arbitrary code execution with the invoking user's privileges. Depending on those privileges and the environment, the attacker could access or modify documents and other user-readable files, steal accessible credentials, or alter subsequent processing. No privilege-escalation mechanism is present in the audited project, so impact is limited to the permissions already held by the process executing the installation.

Remediation
View remediation

Remediation Suggestions

  • Replace the unversioned installation instruction with an explicitly pinned, reviewed version.
  • Maintain dependencies in a lockfile or requirements file with cryptographic hashes, and install them using hash enforcement such as pip install --require-hashes.
  • Explicitly use an approved package index and disable unintended additional indexes to reduce dependency-confusion risk.
  • Install dependencies inside a dedicated virtual environment with least-privilege permissions.
  • Review and pin transitive dependencies where applicable.
  • Prefer a preinstalled and centrally managed dependency rather than performing runtime installation.
  • Periodically scan pinned packages for known vulnerabilities and update them through a controlled review process.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions are broad enough to match many ordinary document-editing requests, which can cause this specialized skill to activate outside its intended scope. That creates routing ambiguity and increases the chance that a user is handled by a workflow with assumptions or capabilities not appropriate for the request, especially since it explicitly takes priority over a general docx skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Keywords like '建议书', '可行性', '立项', and '修改某部分' are generic enough to appear in normal conversation or unrelated writing tasks, making accidental activation likely. In a skill-selection system, overly generic triggers can hijack requests from safer or more appropriate skills and lead to incorrect processing paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow explicitly allows direct execution of 'simple changes' without prompting for backup creation or warning that the original document may be modified in place. In a document-editing skill, this creates a real integrity and availability risk because users may lose the original version or be unable to recover from unintended edits.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The recommended workflow includes pandoc conversion, python-docx modification, and direct XML editing, but omits warnings that these operations can alter formatting fidelity, break document structures, or corrupt DOCX packages if performed incorrectly. Because this skill is specifically intended for professional proposal and feasibility documents, silent formatting loss or corruption can materially damage business deliverables.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. The entire workflow is presented only in Chinese and all examples, labels, and outputs assume Chinese usage, with no explicit user opt-in or statement that the skill is intentionally limited to Chinese-language documents.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.