Back to skill

Security audit

Document Format Skills

Security checks for vulnerabilities and agentic risk

Overview

This is a local DOCX formatting helper with disclosed behavior, but its documentation overstates some options and uses an unpinned runtime dependency.

Use this on copies of documents first, because it rewrites formatting and punctuation and some advertised options are not actually honored. Prefer installing python-docx from a pinned, trusted environment instead of relying on runtime dependency resolution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned Third-Party Dependency Is Downloaded at Runtime

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:17-21, SKILL.md:178-183; equivalent unpinned commands also appear in README.md:25-60 and README_CN.md:20-72
Vulnerability Type: Supply-chain risk caused by runtime resolution of an unpinned dependency
Risk Level: Medium

Vulnerable Code Snippet

markdown
### Format diagnostics

Analyze document issues and output a diagnostic report:

```bash
uv run --with python-docx python3 scripts/analyzer.py input.docx
text

```markdown
## Dependencies

- python-docx

Using `uv run --with python-docx` automatically installs it.

The same runtime installation pattern is documented for the punctuation and formatting scripts:

bash
uv run --with python-docx python3 scripts/punctuation.py input.docx output.docx
uv run --with python-docx python3 scripts/formatter.py input.docx output.docx --preset official

Technical Analysis

The documented commands instruct uv to resolve and install python-docx dynamically whenever a script is executed. The project does not provide a pinned version, lockfile, package hash, or other integrity constraint.

Consequently, the dependency selected during a future execution may differ from the dependency available when the Skill was audited. The effective trusted codebase includes both python-docx and its transitive or build dependencies obtained from the configured package index.

This does not demonstrate that the current python-docx package is malicious. The security issue is that runtime dependency resolution leaves package selection mutable and exposes execution to package-index compromise, a malicious future release, dependency-source misconfiguration, or manipulation of transitive dependencies.

Attack Path

  1. An attacker compromises a relevant package release, transitive dependency, configured package source, or dependency-resolution environment.
  2. A user follows the documented `uv r ...[truncated 1319 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin python-docx and all transitive dependencies to reviewed versions.
  2. Commit a uv.lock file or an equivalent immutable dependency lockfile.
  3. Use hash verification for downloaded distributions where supported.
  4. Install dependencies from an explicitly configured, trusted package index rather than relying on ambient package-source configuration.
  5. Separate dependency installation from document processing. Install and review dependencies during a controlled setup phase instead of downloading them whenever a document is processed.
  6. Run the scripts in an isolated virtual environment or sandbox with minimal filesystem access and no unnecessary network access.
  7. Add automated dependency vulnerability and integrity checks to the release process.
  8. Replace the documented commands with locked execution, for example:
bash
uv sync --frozen
uv run --frozen python scripts/analyzer.py input.docx

The exact command should match the committed lockfile and supported uv version.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

该代码与“格式诊断”部分基本一致,因为它会读取 docx 并分析标点、序号、段落和字体问题。但声明中的关键能力还包括“标点符号修复”“格式统一”以及“输出规范整洁的docx”,这些在当前代码中均未实现。代码没有保存或修改文档,只是打印报告或输出 JSON,并且报告里还建议另行运行 punctuation.py 和 formatter.py 来完成修复与统一,进一步说明本文件只是诊断模块。因此描述明显高于实际行为,存在能力描述不符。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

该代码确实属于文档格式处理/格式统一的一部分,因此方向上相关;但声明描述的是一个更全面的文档整理工具,包含格式诊断、标点符号修复、格式统一,并暗示能把杂乱文档整体整理成规范整洁的 docx。实际代码只对 docx 段落行距进行有限调整,且通过简单规则跳过疑似标题段落,没有任何标点修复、格式诊断、或其他综合排版清理逻辑。因此描述对能力范围存在明显夸大,属于描述与实际行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个较全面的文档格式处理工具,涵盖格式诊断、标点修复和整体格式统一。实际代码行为非常有限,只对 docx 文档的非空段落设置固定 28pt 行距,不进行诊断,不处理标点,也未见其他版式规范化逻辑。因此代码的实际主要功能明显比声明窄,且声明中的关键能力未被实现,属于描述与行为不匹配。未发现额外越权资源访问或隐藏能力,但主功能范围存在实质性偏差。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

整体上,该代码确实属于文档格式处理/格式统一工具,与声明的大方向一致;但声明中的两个具体能力“格式诊断”“标点符号修复”在代码中并未真正实现。代码只是根据正则和位置判断段落类型,并统一 DOCX 的版式与字体样式,没有对标点进行纠错、替换或规范化,也没有输出独立的诊断结果。因此存在描述与实际功能不完全一致的情况。另有未声明但相对相关的附加能力,如多种格式预设和自动添加页码,不过这些仍属于文档格式化范畴,不是严重越权。综合判断为轻到中度功能描述不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The implemented behavior is narrower than the declared description. The script does process DOCX files and performs punctuation repair, which matches part of the description. However, it does not diagnose document formatting, inspect/report formatting issues, or perform general format unification such as styles, spacing, headings, fonts, alignment, or layout normalization. Its primary function is text-level punctuation normalization within paragraphs and table cells. Therefore the description overstates the tool's capabilities and is not an accurate representation of the supplied code chunk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation states that mixed-language text will 'default to Chinese punctuation,' which imposes a locale-specific formatting policy. Under the policy rules, forcing a specific language/locale behavior without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description, headings, usage instructions, and warnings are all presented exclusively in Chinese. This imposes a specific language on users without any opt-in, alternative language option, or stated region-specific justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file contains multiple user-facing strings exclusively in Chinese, including the module description and the printed report output. Because the script does not offer a user language/locale choice or state that it is intentionally limited to a Chinese-only workflow, it creates a natural-language locale policy concern under the language-choice rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains user-facing natural language in the module docstring and usage/help text only in Chinese. Under the policy, forcing a specific language without offering a user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and formatting rules prescribe Chinese government-document standards, Chinese fonts, and Chinese heading/date patterns as defaults and throughout detection logic. This is a natural-language locale constraint that is not presented as an explicit user opt-in or region-specific limitation in the file, so it can conflict with organizational language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language descriptions and comments that present the skill as Chinese-specific, beginning with the module docstring title and change notes in Chinese. Under the policy, forcing a specific language without user opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The description states the toolkit is for 'Chinese documents' and the rest of the README is centered on Chinese formatting conventions, which is a locale-specific constraint expressed in natural language. There is no explicit user opt-in or alternative locale choice documented in this file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.