Back to skill

Security audit

docx

Security checks for vulnerabilities and agentic risk

Overview

This docx skill has no embedded malware, but it asks for broad command execution and generic automation/API workflows that are not clearly bounded to Word document tasks.

Review before installing. Use this only if you are comfortable with a docx helper that can request read and command-execution authority, and keep usage limited to explicit Word document tasks. Avoid giving it credentials or broad filesystem access unless the specific document operation requires it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger description is overly broad, mixing any mention of Word documents with vague 'Development automation, data analysis, and orchestration' use cases. Overbroad triggers can cause unintended activation of a skill with read and exec capabilities, creating opportunities for unauthorized file access or execution in contexts where the user did not specifically request docx operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The user-facing summary and description are partly in Chinese and partly in English, but the file does not state that language is selectable or limited to a region-specific audience. This can violate language/locale policy expectations by implicitly forcing a locale without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file claims support for docx/dotx processing, yet surrounding sections reference generic automation, GitHub-backed data sources, API keys, and command execution. This inconsistency increases attack surface by normalizing unrelated external access patterns and can mislead downstream systems into granting trust or permissions not needed for document manipulation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is marketed as a docx-specific capability, but the documentation broadens its scope into API usage, command execution, and generic automation steps. This scope mismatch can cause an agent or operator to invoke higher-risk behaviors than expected, especially because the skill declares the exec tool and gives execution-oriented guidance unrelated to Word processing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The automatic-trigger condition states the skill should run whenever the user needs 'related operations' without defining what is in or out of scope. In a skill with ambiguous functionality and privileged tools, this can lead to accidental invocation, unsafe chaining, or misuse beyond document handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.