DOCX Toolkit

Security checks across malware telemetry and agentic risk

Overview

This is a local Word document processing skill with expected file outputs, but users should treat extracted text, images, and optional context manifests as sensitive.

Install only in an environment where you trust the Python dependencies. Run it on documents you are allowed to process, keep output folders private, avoid --context for highly sensitive documents unless you need it, and provide a separate output directory when resizing images to preserve originals.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
72% confidence
Finding
When --context is used, the script writes an image manifest containing nearby paragraph text, section names, and inferred categories to disk. In document-processing workflows, that metadata can materially increase sensitive data exposure by persisting contextual snippets that may include personal, contractual, or regulated information, especially if output directories are shared, synced, or logged.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal