Back to skill

Security audit

文档工具箱专业版

Security checks across malware telemetry and agentic risk

Overview

This document automation skill appears legitimate, but its broad activation scope and handling of sensitive business documents need review before installation.

Install only if you intend to use it for controlled document automation. Before using it on contracts, HR records, financial reports, or customer data, confirm where data is processed, disable or review callback/protocol endpoint integrations unless needed, limit input folders and output/version directories, and require explicit approval before batch runs or shell-command-backed conversions.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger condition is overly broad ('use when improving efficiency, automation, batch processing, workflow optimization'), which can cause the agent to invoke a high-privilege skill for many generic tasks. Because the skill has read/exec/write capabilities and handles sensitive business documents, broad routing increases the chance of unnecessary access to files, command execution, or document generation in contexts where a narrower tool should be used.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill promotes processing sensitive sources such as CSV/Excel/JSON, contracts, HR offers, and protocol endpoint integrations, but the user-facing warnings about privacy, data handling, and possible external transmission are minimal and buried. In this context, the skill is more dangerous because it is aimed at enterprise document workflows that commonly include personal, financial, legal, and confidential data, so users may unknowingly expose sensitive content during automated processing or integration.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.