Back to skill

Security audit

WORD,OFFICE,office,word文档处理工具

Security checks for vulnerabilities and agentic risk

Overview

This is a Word document helper with expected local file read/write behavior and no evidence of hidden persistence, credential access, or data theft.

Install only from a trusted Python package index, consider pinning python-docx, and use safe non-conflicting output paths. Expect Chinese-language documentation and verify the CLI entry point before relying on the command examples.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
SKILL.md:32
Finding

Unpinned Third-Party Python Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:32-38
Vulnerability Type: Unpinned third-party dependency
Risk Level: Low

Vulnerable Code

markdown
- Python 3.6+
- Dependency:
  - `python-docx` (Word document processing)

Install the dependency:
```bash
pip install python-docx
text

### Technical Analysis

The installation instructions retrieve `python-docx` without specifying an exact, reviewed version or validating package integrity with cryptographic hashes. Consequently, installation results can change over time and depend on the package index configured in the execution environment.

The package name appears legitimate, and the audited project contains no evidence that its author controls or intentionally substitutes the dependency. The risk arises if a package release, package-index account, mirror, or local package-index configuration is compromised. Because the implementation imports `docx` when document functions are invoked, malicious code introduced into the installed dependency could execute with the privileges of the process running the Skill.

### Attack Path

1. An attacker compromises a future `python-docx` release, its publishing account, a configured package mirror, or the environment's package-index configuration.
2. A user or Agent follows the documented `pip install python-docx` instruction.
3. Pip resolves and installs the attacker-influenced package because no version or hash constraints are present.
4. The Agent invokes a document-processing operation such as `check_docx_installed`, `create_document`, or `read_document`.
5. The script imports the installed `docx` module, allowing malicious dependency code to execute in the Agent process.

### Impact Assessment

Successful exploitation could execute arbitrary Python code with the same operating-system privileges as the user or Agent process. This may permit access to files, environment variables, credentials, and net
...[truncated 238 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin python-docx to a specific version that has been reviewed and tested:
    bash
    pip install python-docx==<reviewed-version>
    
  2. Maintain dependencies in a lock or requirements file with SHA-256 hashes:
    text
    python-docx==<reviewed-version> \
        --hash=sha256:<verified-package-hash>
    
  3. Install with hash verification enabled:
    bash
    pip install --require-hashes -r requirements.txt
    
  4. Explicitly use a trusted package index and prevent untrusted supplemental indexes from overriding dependency resolution.
  5. Periodically review and update the pinned version after vulnerability and provenance checks.
  6. Run the Skill in a least-privileged, isolated environment with restricted filesystem, credential, and network access to limit the impact of a compromised dependency.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language description, headings, and usage guidance are presented in Chinese throughout the file. Under the stated policy, forcing a specific language without user choice is a locale/language policy violation unless clearly justified or optional.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description advertises creating Word documents and performing batch document operations, both of which can modify the filesystem. The README does not include any user-facing caution about choosing output paths carefully or the possibility of overwriting existing files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description is written entirely in Chinese, which indicates a language-specific presentation without any indication that users can choose another language. The policy explicitly flags language or locale constraints when they are imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's primary documentation is written only in Chinese, and the demo/user-facing outputs throughout the module are also fixed in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.