Back to skill

Security audit

WPS Word Document

Security checks for vulnerabilities and agentic risk

Overview

This DOCX skill is mostly coherent, but it includes under-disclosed network fetching and unsafe file/archive handling that users should review before installing.

Install only if you trust the HTML and DOCX files being processed and can run the skill in a sandbox with limited filesystem and network access. Avoid converting attacker-supplied HTML with remote images, and do not point unpacking outputs at existing important directories.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/html2docx.py:2049
Finding

Unrestricted Remote Image Fetching Enables Blind SSRF

Content
View full analysis
` attribute is requested from the environment running the converter. The implementation does not: - Require explicit authorization for network access. - Restrict destinations to approved hosts. - Reject loopback, private, link-local, multicast, or reserved IP addresses. - Protect cloud instance metadata endpoints. - Revalidate redirect destinations. - Prevent DNS rebinding. - Restrict ports or URL credentials. Fetching external images can support HTML-to-DOCX conversion, but unrestricted network access exceeds the minimum privilege required. Embedded data or approved local image inputs can provide the core conversion functionality without granting arbitrary outbound access. Because request errors are suppressed, this is primarily a blind SSRF primitive. Nevertheless, differences in processing time or whether a valid image is inserted may provide limited information about internal resources. ### Attack Path 1. An attacker supplies or influences the HTML being converted. 2. The attacker inserts an image referencing an internal destination, such as: ```html ``` 3. The converter processes the image and passes its `src` att ...[truncated 1153 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/html2docx.py:2039
Finding

Unbounded Image Downloads and Data-URI Decoding Enable Resource Exhaustion

Content
View full analysis
0: run.add_picture(img_stream, width=Inches(width_inches), height=Inches(height_inches)) else: run.add_picture(img_stream, width=Inches(width_inches)) ``` ### Technical Analysis The implementation loads complete remote responses into memory using `resp.read()` and decodes complete data URIs with `base64.b64decode()`. It does not enforce: - Maximum encoded or decoded data-URI size. - Maximum remote response size. - Maximum cumulative image size per document. - Permitted content types or image formats. - Maximum image dimensions or pixel count. - Compression-ratio or decompression-bomb limits. - A maximum number of images. The ten-second timeout constrains request duration but does not constrain bytes ...[truncated 1173 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/office/_shared.py:80
Finding

Unbounded DOCX Archive Extraction and XML Parsing Permit ZIP-Bomb Denial of Service

Content
View full analysis
None: if output_dir.exists(): shutil.rmtree(output_dir) output_dir.mkdir(parents=True, exist_ok=True) with zipfile.ZipFile(input_docx, "r") as archive: archive.extractall(output_dir) ``` Validation also loads every XML member completely into memory: ```python with zipfile.ZipFile(docx_path, "r") as archive: names = set(archive.namelist()) result["parts"] = len(names) missing = sorted(REQUIRED_PARTS - names) if missing: result["ok"] = False result["errors"].append(f"缺少必要部件: {', '.join(missing)}") for name in sorted(n for n in names if n.endswith(".xml")): try: etree.fromstring(archive.read(name)) except etree.XMLSyntaxError as exc: result["ok"] = False result["errors"].append(f"XML 解析失败 {name}: {exc}") ``` ### Technical Analysis DOCX files are ZIP archives and may be attacker-controlled. The code does not enforce limits on: - Number of archive members. - Size of individual uncompressed members. - Total expanded archive size. - Compression ratio. - XML member size or complexity. - Processing time. - Available disk space. `extractall()` can therefore expand a small compressed file into a much larger directory. Validation separately uses `archive.read(name)`, which loads each XML file entirely into memory before parsing it. Although modern Python versions provide some normalization against common ZIP path traversal patterns, extraction should not rely solely on library defaults. Every archive member shoul ...[truncated 1008 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/office/_shared.py:80
Finding

Unpacking Recursively Deletes an Arbitrary Existing Output Directory

Content
View full analysis
None: if output_dir.exists(): shutil.rmtree(output_dir) output_dir.mkdir(parents=True, exist_ok=True) with zipfile.ZipFile(input_docx, "r") as archive: archive.extractall(output_dir) ``` ### Technical Analysis The unpacking routine recursively deletes any existing path supplied as `output_dir`. There is no: - Approved-workspace boundary. - Confirmation requirement. - Explicit overwrite option. - Check that the destination was created by this operation. - Protection for filesystem roots, home directories, project directories, or unrelated data. - Requirement that the directory be empty. The public `unpack_docx()` function resolves the caller-provided path and passes it to this routine. Recursive deletion is not necessary for basic DOCX extraction; refusing an existing non-empty destination would preserve functionality with substantially lower privilege. Deletion occurs before the input archive has been validated or extraction has succeeded. ### Attack Path 1. A caller, compromised workflow, or attacker-influenced argument selects an existing writable directory as `output_dir`. 2. `unpack_docx()` resolves the path and passes it to `unzip_docx()`. 3. `unzip_docx()` detects that the directory exists. 4. `shutil.rmtree()` recursively removes its contents. 5. The function then attempts to recreate the directory and extract the DOCX. 6. Even if extraction subsequently fails, the original files have already been deleted. ### Impact Assessment The Skill can delete any directory tree writable by its process identity. Depending on runtime permissions, this may include: - User documents and generated artifacts. - Project source files. - Shared workspace data. - Application st ...[truncated 184 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:238
Finding

Troubleshooting Recommends Installation of an Unpinned Runtime Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose says DOCX creation/editing, but the implementation reportedly includes undeclared network retrieval of remote image resources. Hidden or under-declared network behavior is risky because user-provided HTML/content can trigger outbound requests, causing SSRF-like access, data exfiltration, or unexpected contact with attacker-controlled hosts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented purpose says DOCX creation/editing, but the implementation reportedly includes undeclared network retrieval of remote image resources. Hidden or under-declared network behavior is risky because user-provided HTML/content can trigger outbound requests, causing SSRF-like access, data exfiltration, or unexpected contact with attacker-controlled hosts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose says DOCX creation/editing, but the implementation reportedly includes undeclared network retrieval of remote image resources. Hidden or under-declared network behavior is risky because user-provided HTML/content can trigger outbound requests, causing SSRF-like access, data exfiltration, or unexpected contact with attacker-controlled hosts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The imports and later implementation show built-in network retrieval capability that is unrelated to the stated scope of creating or editing DOCX files. In an agent skill, hidden network reachability materially increases risk because untrusted document content can trigger outbound requests during conversion.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/html2docx.py (reported line 759)May include surrounding context.

python
}
            )
            order += 1
    return rules


def match_simple_selector(tag, simple_selector):

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The converter fetches remote image URLs from arbitrary http/https sources during HTML-to-DOCX conversion, which expands a nominally local document-processing skill into a network-capable one. This can leak user/network metadata, enable SSRF-like access to internal resources if attacker-controlled HTML is processed, and violate user expectations about offline/local handling.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs use of file read/write operations and references code paths that may fetch remote resources, but it declares no explicit tool scope or permission boundary. This increases the chance of over-broad execution privileges and makes it harder for the platform to constrain file and network access to only what the skill actually needs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

整份技能说明以中文固定描述技能行为与输出规范,且未见任何允许用户选择语言/locale 的说明。根据规则,若技能隐含强制特定语言而无用户选择或合理限定,属于自然语言层面的语言/区域策略违规。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger language includes broad everyday phrases like '生成文档' or '帮我做个文档', which can cause the skill to activate in situations where the user did not explicitly request DOCX handling. Over-broad activation raises the risk of unnecessary file generation, unintended document conversion, and invocation of higher-risk file/network-capable workflows.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

md
**参数:**

| 参数           | 类型                | 默认值      | 说明                                                                                |
| -------------- | ------------------- | ----------- | ----------------------------------------------------------------------------------- |
| `input_docx`   | `str`               | —           | 输入文件完整路径                                                                    |
| `output_docx`  | `str`               | —           | 输出文件完整路径                                                                    |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file contains multiple user-facing error and CLI help strings in Chinese, which imposes a specific language on users. Under the policy, language-specific behavior without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The inline documentation for _load_image_bytes presents remote HTTP/HTTPS fetching as a normal supported source alongside data URIs, which conflicts with the broader skill intent of a document-generation tool that should not need undeclared network behavior. This documentation actively normalizes behavior outside the manifest-described scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Remote image retrieval occurs silently, with no warning that converting attacker-supplied HTML may contact external hosts. This reduces informed consent and makes data exfiltration, tracking, and unexpected network access more likely in environments where users expect local-only document generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file contains user-facing natural-language strings in Chinese for error reporting (目录不存在, DOCX 验证失败) while the rest of the CLI interface is otherwise generic and does not offer any language selection or document that the tool is Chinese-only. This is a natural-language policy concern because it imposes a specific locale on users without opt-in or stated justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code emits several user-visible error messages in Chinese, while the CLI description is in English. This forces a specific language for operational output without user opt-in or an explained region-specific requirement, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring and multiple user-facing messages are written only in Chinese, including runtime error and status strings. This imposes a specific language on users without offering a locale choice or documenting that the skill is intentionally Chinese-only.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Saving the generated document is a filesystem write operation, but there is no confirmation prompt or user-facing disclosure immediately before performing the write. The docstring notes the output path parameter, but the code itself does not warn the user at runtime before modifying the filesystem.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.