Back to skill

Security audit

Word Docx V102 Tool Free

Security checks across malware telemetry and agentic risk

Overview

This Word document skill has a coherent purpose, but it asks for broad write and command execution authority without clear limits or user-confirmation rules.

Install only if you are comfortable letting the agent run local commands and change Word-related files. Use it on a bounded working folder, review any command before execution, and keep backups of documents before asking it to modify, export, or delete content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The skill explicitly requests the exec tool in addition to read/write for a Word document workflow, but the manifest and body do not constrain what commands may be run. For a document-processing skill, unrestricted command execution greatly expands the attack surface and could let the agent run arbitrary system commands, access unrelated files, or chain into further compromise if the skill is invoked with attacker-influenced inputs.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The invocation guidance is broad and generic, with vague examples like formatting reports or enabling tracking without clear trigger boundaries, allowed inputs, or safety preconditions. In an agent setting, ambiguous activation criteria can cause the skill to engage in contexts the user did not clearly intend, increasing the chance of unintended file operations or escalation into exec-backed behavior.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises creation, query, export, modification, and delete-style operations together with write/exec capability, yet it provides no clear warning that files may be changed or that commands may be executed on the host. This omission makes dangerous side effects less visible to users and upstream agents, increasing the likelihood of silent document tampering, data loss, or risky command execution.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.