Back to skill

Security audit

Word Template Filler

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Word document automation guide with no hidden scripts, network behavior, credential handling, or persistence.

Install this if you need Word-based template filling on Windows. Keep original templates backed up, review the document and image paths before running generated code, and avoid the WINWORD.EXE taskkill debugging command when unsaved Word documents may be open.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.