Back to skill

Security audit

文档工具箱免费版

Security checks across malware telemetry and agentic risk

Overview

This skill is a local DOCX document helper; its activation wording is too broad, but the artifact does not show hidden data access, exfiltration, or destructive behavior.

Install only if you want an agent to read, create, edit, and render local DOCX files. Review generated documents before sharing them, be cautious with package-manager commands such as pip, brew, or apt-get, and treat the optional callback_url field as something that could send workflow status outside the local machine if an implementation later supports it.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger condition '需要代码生成、编程辅助、调试测试、开发部署时使用' is so broad that the skill may activate in many unrelated contexts. Over-broad activation increases the chance that an agent invokes exec-enabled document tooling unexpectedly, expanding attack surface and creating opportunities for prompt-driven misuse.

Vague Triggers

Low
Confidence
82% confidence
Finding
The long capability-keyword list is overly expansive and vague, which can cause accidental or unnecessary routing to this skill. In an exec-capable skill, imprecise activation cues are risky because they can lead to unintended command execution pathways even when a request is only loosely related.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.