Back to skill

Security audit

Word Document Creator

Security checks for vulnerabilities and agentic risk

Overview

This Word document skill is mostly aligned with document creation, but it needs Review because its documented invocation does not match the script, it can overwrite local files without safeguards, and it includes unexplained persistence metadata.

Install only if you are comfortable with a Windows-only Word automation skill that can create or overwrite local .docx files. Before use, the publisher should add real argument parsing, remove or replace the unsafe shell=True example, require confirmation before overwriting files, constrain output paths, and remove or clearly document the mem9 storage identifiers and retention behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
examples/example_usage.py:103
Finding

Shell Command Injection in the Documented Command-Line Execution Pattern

Content
View full analysis

Vulnerability Details

File Location: examples/example_usage.py, lines 103–116
Vulnerability Type: Shell command injection through unsafe command-string construction
Risk Level: Medium

Vulnerable Code

python
# 转换为JSON字符串
content_json = json.dumps(content_list, ensure_ascii=False)

output_path = r"E:\Desktop\技术文档模板.docx"

# 构建命令行
cmd = f'python scripts/word_creator.py --title "{title}" --content \'{content_json}\' --output "{output_path}"'

print(f"命令行调用示例:")
print(f"  {cmd}")

# 实际执行(注释掉,仅展示)
# import subprocess
# result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
# print(result.stdout)
# print(result.stderr)

Technical Analysis

The example constructs a shell command by directly interpolating title, content_json, and output_path into a single string. It then demonstrates executing that string with subprocess.run(..., shell=True).

Shell quoting does not constitute safe input validation. If any interpolated value contains shell metacharacters, quote delimiters, command separators, redirection operators, or command-substitution syntax, the value can escape its intended argument and be interpreted as a separate command by the operating-system shell.

The execution lines are currently commented out, so the checked-in example does not directly execute the command. However, the comments explicitly instruct users to uncomment this pattern for actual use. The vulnerability becomes exploitable when the example is enabled, copied into production code, or adapted to process externally supplied document fields.

Attack Path

  1. An application accepts an attacker-controlled document title, content value, or output path.
  2. The application uses the demonstrated f-string to place that value into cmd.
  3. The attacker includes shell syntax that closes the surrounding quote and appends another command.
  4. The application invokes subprocess.run(cmd, shell=True, ...).
  5. The operating-system shell parses the ...[truncated 919 chars]
Remediation
View remediation

Remediation Suggestions

Do not pass dynamically constructed command strings to a shell. Invoke Python with an argument list and leave shell processing disabled:

python
import subprocess
import sys

result = subprocess.run(
    [
        sys.executable,
        "scripts/word_creator.py",
        "--title",
        title,
        "--content",
        content_json,
        "--output",
        output_path,
    ],
    shell=False,
    capture_output=True,
    text=True,
    check=True,
)

Additional hardening measures:

  1. Remove the insecure shell=True example so users are not encouraged to copy it.
  2. Use sys.executable instead of a bare python command to select the current trusted interpreter.
  3. Implement and validate the advertised command-line arguments in word_creator.py before documenting command-line use.
  4. Restrict output paths to an approved directory when paths can originate from untrusted users.
  5. Validate input types and impose reasonable length limits on titles and document content.
  6. Handle subprocess.CalledProcessError without exposing sensitive command output or local path details.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · examples/example_usage.py (reported line 119)May include surrounding context.

python
# 实际执行(注释掉,仅展示)
    # import subprocess
    # result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
    # print(result.stdout)
    # print(result.stderr)

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · scripts/word_creator.py (reported line 48)May include surrounding context.

python
sys.stderr.reconfigure(encoding='utf-8')
except AttributeError:
    os.environ['PYTHONIOENCODING'] = 'utf-8'
    os.system('chcp 65001 > nul')

# ==========================================
# [清洗] 智能文本清洗

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · scripts/word_creator_fixed.py (reported line 50)May include surrounding context.

python
sys.stderr.reconfigure(encoding='utf-8')
except AttributeError:
    os.environ['PYTHONIOENCODING'] = 'utf-8'
    os.system('chcp 65001 > nul')

# ==========================================
# [清洗] 智能文本清洗

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is presented entirely in Chinese and describes localized defaults such as Chinese font choices, but it does not state that the skill is China-specific or provide any user opt-in for language/locale. This creates a natural-language policy concern because it effectively imposes a specific language/locale on users without documented choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill accepts a user-specified output path and is designed to create a document on disk, but it does not warn that existing files may be overwritten or that arbitrary filesystem locations may be targeted. In agent settings, this can lead to unintended data loss or writes into sensitive directories if path handling is not constrained.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is for Word document creation, but it documents storing 'successful experience' in a mem9 database with a concrete database ID. This introduces an unrelated persistence capability that could retain operational data or user-derived content outside the stated document-generation purpose, expanding the data exposure surface without clear necessity or consent.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The embedded mem9 database identifier and plain-language note about stored experience suggest persistent storage associated with the skill, but without any security, privacy, or data-handling boundaries. Even in documentation, exposing a stable identifier and implying retention can facilitate unauthorized correlation, misuse of stored data, or hidden state that affects future runs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The function writes a Word document directly to an arbitrary output path and will overwrite an existing file without explicit confirmation or protective checks. In an agent/skill context, this can cause unintended local file modification or destruction if the path is influenced by upstream inputs or mistaken automation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

User-facing strings and comments throughout the file are presented only in Chinese, including fatal error output and runtime status messages. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code performs a file write to the caller-provided output path via doc.save(output_path). Although the script prints progress messages, it does not explicitly warn the user that an existing file at that path may be created or overwritten, and there is no confirmation prompt before the write.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This is a manifest file, so vague-trigger checks apply. The description explains what the skill does but provides no explicit trigger phrases, activation conditions, or exclusions, leaving unclear when the skill should be invoked versus other document-related skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Natural-language policy checks apply to all file types. The description and multiple user-facing strings are Chinese-only, which effectively forces a specific language without any opt-in or justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · examples/example_usage.py (reported line 195)May include surrounding context.

python
},
  
  "files": {
    "skill_md": "skills/word-document-creator/SKILL.md",
    "main_script": "skills/word-document-creator/scripts/word_creator.py",
    "example_usage": "skills/word-document-creator/examples/example_usage.py",
    "config_file": "skills/word-document-creator/skill.json (本文件)"

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skill.json (reported line 73)May include surrounding context.

json
},
  
  "files": {
    "skill_md": "skills/word-document-creator/SKILL.md",
    "main_script": "skills/word-document-creator/scripts/word_creator.py",
    "example_usage": "skills/word-document-creator/examples/example_usage.py",
    "config_file": "skills/word-document-creator/skill.json (本文件)"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code file contains user-facing natural-language strings and documentation that assume Chinese as the required language. Under the policy rule, forcing a specific language without opt-in can be a locale/language policy issue when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language comment and implementation explicitly force Western text to use Arial for consistency, rather than offering a user language/locale or font choice. This is a natural-language policy concern because it imposes a fixed formatting choice tied to language/script behavior without opt-in or documented user selection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The function creates an intermediate Word document in the system temp directory as part of its workflow. Although this is later cleaned up, the code does not clearly disclose to users that an additional temporary file containing document content may exist on disk during processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The cleanup block removes a generated temporary .docx file with os.remove(temp_path). While this is benign housekeeping, it is still a file deletion operation and there is no explicit user-facing warning or documentation indicating that the script creates and later deletes temp files.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest embeds unrelated external backup/service metadata, including what appear to be persistent storage and tenant identifiers, in a Word document creation skill. Even if these are not active secrets, they expose unnecessary internal integration context and may aid service enumeration, cross-tenant targeting, or accidental coupling to external systems outside the declared skill scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.