Back to skill

Security audit

Office Automation Pro

Security checks for vulnerabilities and agentic risk

Overview

This office automation skill is broadly purpose-aligned, but it asks for command execution while promoting bulk email, cloud integrations, scheduling, and sensitive business-data workflows without clear limits or consent gates.

Review this skill carefully before installing. Use it only in a constrained workspace, avoid giving it broad filesystem access, do not store real email passwords unless you trust the publisher and runtime, and require manual review before sending emails, touching cloud storage, processing HR/finance/customer data, or running shell commands.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill makes strong safety claims such as '移除风险代码' and '数据本地处理/不上传云端' while also advertising exec capability, email sending, cloud storage, and third-party integrations. These conflicting assurances can mislead users and agents into trusting the skill more than warranted, reducing scrutiny around actions that may execute commands or transmit data externally.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Granting a generic exec capability to a Markdown-driven office automation skill materially increases risk because natural-language requests can be translated into arbitrary local command execution. In this context, document conversion and reporting tasks do not justify unrestricted shell access, creating a path for file tampering, data exfiltration, or execution of unsafe tooling if the agent over-interprets user intent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords are broad terms like 'office', 'automation', and '数据整理', which are likely to match normal conversation and activate the skill in contexts the user did not intend. Because this skill includes impactful automation and exec-enabled behavior, accidental invocation increases the chance of unintended file processing, report generation, or outbound communication.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill prominently describes bulk email, file generation/conversion, and other high-impact automation without equally prominent warnings about privacy, external transmission, filesystem modification, and execution side effects. In an office context, these operations often involve sensitive HR, finance, or customer data, so under-warning users materially raises the risk of accidental disclosure or disruptive bulk actions.

Static analysis

No suspicious patterns detected.