Back to skill

Security audit

Office Reader

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local document reader with disclosed file-reading behavior, but users should note the broad local-file access model, missing script implementation, and unpinned dependency install guidance.

Install this only if you are comfortable letting the agent read document paths you explicitly provide. Prefer using a virtual environment, pinning dependency versions, and reviewing or obtaining the missing office-reader.ps1 implementation before relying on it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:33
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 33-37
Vulnerability Type: Unpinned and integrity-unverified third-party dependencies
Risk Level: Medium

Vulnerable Code:

powershell
pip install openpyxl pandas python-docx python-pptx pdfplumber

Technical Analysis

The documented installation command retrieves five Python packages and their transitive dependencies from pip's configured package index without exact version constraints, cryptographic hashes, a lockfile, or an explicitly trusted index.

Consequently, the dependency set can change after the skill has been reviewed. Python package installation can execute package-controlled build or installation logic, so a compromised upstream release, transitive dependency, or configured package index could introduce code execution on the user's system. The package names shown are established names and provide no direct evidence of typosquatting or an actively malicious dependency; the risk arises from mutable, unverified dependency resolution.

Attack Path

  1. A user follows the dependency installation instructions in README.md.
  2. pip resolves the named packages and their transitive dependencies using the user's configured package index.
  3. An attacker compromises an upstream package or dependency release, or controls/misconfigures the package index used by the victim.
  4. pip downloads the attacker-controlled distribution because no reviewed versions or hashes constrain resolution.
  5. Malicious build or installation logic executes with the privileges of the user running pip. Malicious runtime code may also execute later when the dependency is imported.

Impact Assessment

Successful exploitation could allow arbitrary code execution with the privileges of the account performing the installation. The attacker could access or modify files available to that account, read environment variables and application data, alter the Python envi ...[truncated 424 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create a reviewed requirements or lock file containing exact dependency versions, including all transitive dependencies.

  2. Generate and record cryptographic hashes for every permitted distribution.

  3. Install dependencies with hash verification, for example:

    powershell
    python -m pip install --require-hashes -r requirements.txt
    
  4. Configure and document an explicitly trusted package index rather than relying on arbitrary user-level pip configuration.

  5. Review new dependency versions before updating the lock file, and use automated dependency and provenance scanning.

  6. Install dependencies in an isolated virtual environment under a non-privileged account.

  7. Remove dependencies not required by the delivered implementation. In particular, reconcile the documentation's inconsistent references to pypdf and pdfplumber.

  8. Include the declared office-reader.ps1 implementation in the package so its actual dependency usage and security properties can be audited.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises very broad natural-language triggers such as '读取 ...' and '看看这个 Excel 文件 ...' without defining clear boundaries, confirmation requirements, or disallowed path classes. In an agent setting, this can cause the skill to activate on ambiguous user input and read arbitrary local files, increasing the risk of unintended sensitive file disclosure from the host environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The README presents all user-facing instructions in Chinese, including usage examples and operational guidance, with no indication that the skill supports other languages or that Chinese is a required locale. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a compliance issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

整份技能文档和交互示例均默认使用中文,且未说明这是面向特定中文区域用户的受限技能,也未给出用户可选择其他语言的选项。根据语言/区域政策,若无明确的地域性理由或用户选择机制,强制单一语言可能构成自然语言策略问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.