Back to skill

Security audit

Manuscript Math Docx Qc

Security checks for vulnerabilities and agentic risk

Overview

This manuscript QC skill is mostly coherent, but it tells agents to modify the skill's own persistent instructions without requiring user review.

Review this skill before installing because its normal manuscript QC commands are broadly reasonable, but the self-update rule should be removed or changed to write proposed changes to a separate review file that a human approves before SKILL.md is modified.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:21
Finding

Persistent Skill Self-Modification from Untrusted Manuscript Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 21–24
Vulnerability Type: Persistent agent memory poisoning through automatic Skill modification
Risk Level: Medium

markdown
## Maintenance Rule

Treat this skill as a living checklist. When using it on a real manuscript and discovering a reusable failure mode, formula pattern, DOCX/PDF conversion issue, figure-layout fix, table-rendering fix, or submission-package synchronization problem, update this `SKILL.md` before finishing if the lesson is likely to recur.

Only add generalizable lessons. Do not add project-specific paths, manuscript titles, private author details, transient filenames, or one-off numerical results unless they describe a reusable workflow pattern.

Technical Analysis

The Skill instructs the agent to update its own persistent instruction file using lessons learned while processing a manuscript. Manuscripts and related project files are task inputs and may be controlled by an untrusted party. Allowing conclusions derived from those inputs to become durable Skill instructions breaks the trust boundary between untrusted task data and persistent agent state.

The requirement that additions be “generalizable” and omit private details helps limit accidental disclosure, but it does not establish provenance, require human review, or prevent malicious instructions from being framed as reusable workflow advice. Once written into SKILL.md, such content may be loaded as authoritative instructions in later sessions.

Attack Path

  1. An attacker supplies a manuscript or associated project file containing misleading workflow guidance or adversarial content disguised as a recurring document-conversion issue.
  2. The agent processes that input while following this Skill.
  3. The agent interprets the attacker-controlled guidance as a reusable lesson.
  4. Following the maintenance rule, the agent writes a new rule into SKILL.md.
  5. Future agents load the modified Skill and ...[truncated 801 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the instruction requiring agents to modify SKILL.md automatically.
  • Treat manuscripts, document metadata, conversion output, and associated project files as untrusted data that must not become persistent agent instructions.
  • Write proposed lessons to a separate, non-authoritative review file such as PROPOSED_SKILL_CHANGES.md.
  • Require explicit human approval before incorporating any proposed rule into SKILL.md.
  • Record the source and rationale for each proposal so reviewers can assess provenance and determine whether it was influenced by untrusted content.
  • Validate proposed changes against an allowlist of permitted documentation topics and reject instructions involving credentials, network access, arbitrary command execution, privilege changes, persistence, or access outside the active project.
  • Review changes as a patch and run security checks before publishing or loading the updated Skill in future sessions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
able-rendering fix, or submission-package synchronization problem, update this `SKILL.md` before finishing if the lesson is likely to recur.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

The skill includes a destructive shell command, rm -rf build/pdf_check/pages, without safety guards or validation of the target path. In an agent-executed context, parameter/path abuse, variable substitution mistakes, symlink tricks, or running from an unexpected working directory could cause deletion of unintended files beyond the intended build artifact directory.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

text
   - Render pages for visual review:
     ```bash
     rm -rf build/pdf_check/pages
     mkdir -p build/pdf_check/pages
     pdftoppm -png -r 130 build/pdf_check/manuscript.pdf build/pdf_check/pages/page
     ```

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · examples/improved/qc_commands.sh (reported line 19)May include surrounding context.

sh
soffice --headless --convert-to pdf --outdir "${PDF_DIR}" "${OUT_DIR}/improved-manuscript.docx"
pdfinfo "${PDF_DIR}/improved-manuscript.pdf" | rg 'Pages|Page size|File size'

rm -f "${PAGES_DIR}"/page-*.png
pdftoppm -png -r 130 "${PDF_DIR}/improved-manuscript.pdf" "${PAGES_DIR}/page"
ls -lh "${PAGES_DIR}"

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 34)May include surrounding context.

Example for Codex-compatible local skill folders:

bash
mkdir -p ~/.codex/skills
cp -R manuscript-math-docx-qc ~/.codex/skills/

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 34)May include surrounding context.

Example for Codex-compatible local skill folders:

bash
mkdir -p ~/.codex/skills
cp -R manuscript-math-docx-qc ~/.codex/skills/

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This shell script creates directories and files, converts documents via external tools, writes a temporary log, and deletes existing PNG files, but it provides no confirmation prompt, visible user-facing notice, or inline documentation about these side effects. For a code file, these safety-relevant filesystem changes lack any disclosure within the script itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.