Back to skill

Security audit

docx

Security checks across malware telemetry and agentic risk

Overview

The skill claims to handle Word documents, but it also requests broad command execution and API credential workflows without clear scoping or justification.

Review before installing. Use this only for explicit DOCX/DOTX tasks, avoid providing API keys unless the specific need is explained, and require confirmation before running commands or modifying files. Prefer a version that narrows triggers to Word documents and documents exact command, file, and credential boundaries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented as a DOCX manipulation tool, but the documentation expands into generic API usage, credential setup, network access, and command execution workflows unrelated to narrowly scoped Word document handling. This scope mismatch can mislead agents and users into granting broader capabilities than expected, increasing the chance of unintended system actions or data exposure.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The documentation instructs users to configure API keys, establish API connections, and invoke external interfaces without explaining why a local DOCX skill needs remote credentials. Unnecessary credential handling broadens the attack surface and creates opportunities for secret exposure, exfiltration, or misuse of external services under the guise of document processing.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
Advertising command execution for a DOCX skill grants far more power than is typically needed for document reading or editing. In an agent environment, this can enable arbitrary local commands, file tampering, privilege misuse, or staging of follow-on attacks if the skill is invoked with attacker-influenced inputs.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger description is broad and ambiguous, mixing Word-document handling with generic development automation, data analysis, and workflow orchestration. Overbroad activation criteria increase the likelihood that the skill is invoked in contexts where its read/exec capabilities are unnecessary, potentially exposing files or causing unintended actions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The condition 'automatically trigger when the user needs related operations' is too vague to constrain activation safely. In an automated agent platform, vague trigger text can cause this skill to run opportunistically and expose its broader capabilities in situations where the user did not intend document processing or command execution.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill describes document creation and editing but does not prominently warn that it may modify files, overwrite content, or affect templates. Missing upfront modification-risk warnings can lead users or orchestrators to invoke the skill without appropriate backups, confirmations, or guardrails.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation references API keys, external connectivity, and command execution without a clear, early warning about credential sensitivity and host-level impact. Users may unknowingly provide secrets or authorize system actions under the assumption that this is a simple document skill, which heightens the risk of secret leakage and unsafe execution.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.