Back to skill

Security audit

minimax-docx

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real DOCX automation skill, but its setup process can make broad system changes and execute a remote installer, so it should be reviewed before installation.

Install only if you are comfortable with a setup script that may install system packages, download and run Microsoft's .NET installer, update shell startup configuration, and restore packages from NuGet. Prefer reviewing or running setup manually, using --minimal where appropriate, and avoiding installation in sensitive environments unless these host changes are acceptable.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/setup.sh:101
Finding

Remote .NET Installer Downloaded and Executed Without Integrity Verification

Content
View full analysis
> "$HOME/.bashrc" ``` ### Technical Analysis The setup process downloads a mutable shell script from an external URL and executes it immediately without checking a cryptographic checksum or digital signature. Although the URL uses HTTPS and belongs to Microsoft's official domain, transport encryption alone does not establish that the retrieved file is the exact payload reviewed by the project author. The effective installer can change after the Skill package has been audited. A compromise of the upstream distribution infrastructure, DNS or certificate trust chain, an enterprise TLS-inspection proxy, or the remote artifact itself could cause attacker-controlled shell code to be delivered and executed. The fixed path `/tmp/dotnet-install.sh` also creates a local race and symlink risk in shared environments. Another local user could potentially prepare or replace that path while setup is running. The unconditional overwrite reduces but does not fully eliminate race conditions between download, permission modification, and execution. ### Attack Path 1. A user follows the Skill instruction to run `bash scripts/setup.sh`. 2. The sc ...[truncated 1553 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (110)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is declared as a document-processing helper but reportedly performs package installation, downloads external installer scripts, modifies shell startup files, changes permissions, and builds projects. That is a major escalation from content processing to arbitrary host modification, creating substantial supply-chain and persistence risk if automatically executed by an agent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is declared as a document-processing helper but reportedly performs package installation, downloads external installer scripts, modifies shell startup files, changes permissions, and builds projects. That is a major escalation from content processing to arbitrary host modification, creating substantial supply-chain and persistence risk if automatically executed by an agent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is declared as a document-processing helper but reportedly performs package installation, downloads external installer scripts, modifies shell startup files, changes permissions, and builds projects. That is a major escalation from content processing to arbitrary host modification, creating substantial supply-chain and persistence risk if automatically executed by an agent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is declared as a document-processing helper but reportedly performs package installation, downloads external installer scripts, modifies shell startup files, changes permissions, and builds projects. That is a major escalation from content processing to arbitrary host modification, creating substantial supply-chain and persistence risk if automatically executed by an agent.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
91% confidence
Finding

The manifest contains metadata-poisoning indicators, including unusual AIGC provenance fields and opaque reserved codes adjacent to routing metadata. Even if not overtly malicious, such metadata can be used to bias trust decisions, conceal provenance issues, or interfere with downstream tooling that interprets skill manifests.

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
---
AIGC:
    ContentProducer: Minimax Agent AI
    ContentPropagator: Minimax Agent AI
    Label: AIGC
    ProduceID: 9d5a8b3d82a01e0f24fae0fc2985a5c1
    PropagateID: 9d5a8b3d82a01e0f24fae0fc2985a5c1
    ReservedCode1: 304402202866606e6ad9dc0e4f624c67e85f82e9617260f7346116caa0a1fdb9f128680c02202f46fdfd4daab5f6da467fd0b323b4512ec66ce0e30cab8379ef68787ac95abb
    ReservedCode2: 304502206044c98043ad51077bc4cfd8d35829415d3883454a872d97e808b06c66e75a1d022100c6eec4cff27ee43cc2783b3e9a1af0b6b9812219bf6af5c78897f8e67f13540c
description: |
    Professional DOCX document creation, editing, and formatting using OpenXML SDK (.NET). Three pipelines: (A) create new documents from scratch, (B) fill/edit content in existing documents, (C) apply template formatting with XSD validation gate-check. MUST use this skill whenever

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill mandates use for very broad classes of ordinary document-related requests, effectively trying to capture routing for many benign conversations. In an agent ecosystem, this can become prompt/tool poisoning because it pressures the orchestrator to invoke a shell-capable skill far more often than necessary.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list contains highly generic terms that are likely to match normal conversation and over-activate the skill. Because the skill also exposes shell-oriented workflows, over-broad triggering increases the chance of unnecessary or unsafe tool invocation.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/cjk_typography.md (reported line 73)May include surrounding context.

xml
<w:rFonts
  w:ascii="Calibri"        <!-- Latin characters (U+0000–U+007F) -->
  w:hAnsi="Calibri"        <!-- Latin extended, Greek, Cyrillic -->
  w:eastAsia="SimSun"      <!-- CJK Unified Ideographs, Kana, Hangul -->
  w:cs="Arial"             <!-- Arabic, Hebrew, Thai, Devanagari -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design_good_bad_examples.md (reported line 26)May include surrounding context.

└──────────────────────────────────┘

text
```xml
<!-- H1: bold but same size as body — no visual separation -->
<w:rPr><w:b/><w:sz w:val="24"/></w:rPr>
<!-- Body -->
<w:rPr><w:sz w:val="24"/></w:rPr>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design_good_bad_examples.md (reported line 77)May include surrounding context.

text
```xml
<w:rPr><w:b/><w:sz w:val="56"/></w:rPr>  <!-- 28pt heading -->
<w:rPr><w:sz w:val="20"/></w:rPr>         <!-- 10pt body -->

GOOD: H1=20pt with body=11pt (ratio ~1.8x)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design_good_bad_examples.md (reported line 108)May include surrounding context.

xml
<w:pPr>
  <w:spacing w:line="240" w:lineRule="auto"/>  <!-- 1.0 spacing (240/240) -->
  <w:spacing w:after="0"/>                     <!-- no paragraph gap -->
</w:pPr>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design_principles.md (reported line 56)May include surrounding context.

text

```xml
<!-- Page margins: 1 inch = 1440 twips on all sides -->
<w:pgMar w:top="1440" w:right="1440" w:bottom="1440" w:left="1440"
         w:header="720" w:footer="720" w:gutter="0"/>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design_principles.md (reported line 299)May include surrounding context.

md
<w:spacing w:before="360" w:after="120"/>
</w:pPr>

<!-- Body paragraph: 0pt before, 8pt after -->
<w:pPr>
  <w:spacing w:before="0" w:after="160"/>
</w:pPr>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design_principles.md (reported line 550)May include surrounding context.

md
</w:rPr>
</w:style>

<!-- Apply consistently: every H2 references the style -->
<w:p>
  <w:pPr>
    <w:pStyle w:val="Heading2"/>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/openxml_encyclopedia_part3.md (reported line 1030)May include surrounding context.

csharp
// <w:r>
//   <w:rPr>
//     <w:b/>  <!-- New: bold -->
//     <w:rPrChange w:id="7" w:author="Bob" w:date="2026-03-22T11:00:00Z">
//       <w:rPr/>  <!-- Old: no formatting -->
//     </w:rPrChange>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/scenario_b_edit_content.md (reported line 84)May include surrounding context.

When the entire search text is within a single w:r (run):

xml
<!-- Before -->
<w:r>
  <w:rPr><w:b /></w:rPr>
  <w:t>{{companyName}}</w:t>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/scenario_c_apply_template.md (reported line 164)May include surrounding context.

Critical distinction: w:styleId vs w:name:

xml
<!-- styleId="1" but name="heading 1" -->
<w:style w:type="paragraph" w:styleId="1">
  <w:name w:val="heading 1"/>
  <w:basedOn w:val="a"/>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/scenario_c_apply_template.md (reported line 246)May include surrounding context.

xml
   <!-- Source -->
   <w:pPr><w:pStyle w:val="Heading1"/></w:pPr>
   <!-- After mapping -->
   <w:pPr><w:pStyle w:val="1"/></w:pPr>

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

ResolveComment accepts a specific commentId but does not use it to select the target element; instead it marks the first matching extensible comment node as done. This can resolve the wrong comment, corrupt review state, and in a professional DOCX-editing skill may cause users to believe an issue or approval item was closed when it was not, which is especially risky for contracts, reports, and formal review records.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/dotnet/MiniMaxAIDocx.Core/Samples/HeaderFooterSamples.cs (reported line 24)May include surrounding context.

text
///   <w:headerReference w:type="default" r:id="rId7"/>
///   <w:footerReference w:type="default" r:id="rId8"/>
///   <w:headerReference w:type="first" r:id="rId9"/>
///   <w:titlePg/>   <!-- needed to activate first-page header/footer -->
/// </w:sectPr>
///
/// Header/Footer XML (in separate part):

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/dotnet/MiniMaxAIDocx.Core/Samples/HeaderFooterSamples.cs (reported line 490)May include surrounding context.

text
///       <w:gridCol w:w="3120"/> <w:gridCol w:w="3120"/> <w:gridCol w:w="3120"/>
    ///     </w:tblGrid>
    ///     <w:tr>
    ///       <w:tc> <!-- left: logo text -->  </w:tc>
    ///       <w:tc> <!-- center: title -->    </w:tc>
    ///       <w:tc> <!-- right: page num -->  </w:tc>
    ///     </w:tr>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/dotnet/MiniMaxAIDocx.Core/Samples/TableSamples.cs (reported line 274)May include surrounding context.

text
///     <w:tblBorders>
    ///       <w:top w:val="single" w:sz="12" w:space="0" w:color="000000"/>
    ///       <w:bottom w:val="single" w:sz="12" w:space="0" w:color="000000"/>
    ///       <!-- No left, right, insideV borders -->
    ///       <w:insideH w:val="none" w:sz="0" w:space="0" w:color="auto"/>
    ///       <w:insideV w:val="none" w:sz="0" w:space="0" w:color="auto"/>
    ///     </w:tblBorders>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/dotnet/MiniMaxAIDocx.Core/Samples/TableSamples.cs (reported line 552)May include surrounding context.

text
/// XML:
    /// <w:tblGrid>
    ///   <w:gridCol w:w="1440"/>   <!-- 1 inch -->
    ///   <w:gridCol w:w="4680"/>   <!-- 3.25 inches -->
    ///   <w:gridCol w:w="3240"/>   <!-- 2.25 inches -->
    /// </w:tblGrid>
    ///

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/dotnet/MiniMaxAIDocx.Core/Samples/TableSamples.cs (reported line 865)May include surrounding context.

text
/// Row 1: <w:tcPr><w:vMerge w:val="restart"/></w:tcPr>
    ///         <w:p><w:r><w:t>Visible content</w:t></w:r></w:p>
    /// Row 2: <w:tcPr><w:vMerge/></w:tcPr>
    ///         <w:p/>   <!-- MUST still have a paragraph, even though cell is merged -->
    /// Row 3: <w:tcPr><w:vMerge/></w:tcPr>
    ///         <w:p/>   <!-- MUST still have a paragraph -->
    ///

Static analysis

No suspicious patterns detected.