Back to skill

Security audit

DOCX Toolkit

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local Word-document extraction and image-compression toolkit, with no evidence of hidden execution, exfiltration, persistence, or credential access.

Install dependencies in an isolated virtual environment, preferably with pinned versions. Use explicit output directories, especially for image compression, and avoid enabling --context unless you are comfortable saving nearby paragraph text into image_manifest.json. Treat extracted images, text files, and manifests as potentially sensitive copies of the original documents.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:50
Finding

Unpinned Third-Party Dependencies Installed Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 50-52
Vulnerability Type: Supply-chain exposure through mutable dependency resolution
Risk Level: Medium

Vulnerable Code:

bash
Install:
pip3 install python-docx olefile Pillow

Technical Analysis

The documented installation command installs three third-party packages without version constraints, cryptographic hashes, a lockfile, or an explicitly trusted package index. Consequently, package selection depends on the mutable state of the Python package index configured in the user's environment at installation time.

This does not establish that python-docx, olefile, or Pillow are malicious. The vulnerability is that the installation procedure does not ensure users receive the same reviewed artifacts. If a package release, transitive dependency, package-index account, or configured index is compromised, pip may retrieve code that was not reviewed as part of this Skill.

Python packages can execute code during installation or when imported. All four scripts import one or more of these dependencies, meaning a malicious resolved package could also execute when a user invokes the documented document-processing functionality.

Attack Path

  1. An attacker compromises a listed package, one of its transitive dependencies, or a package index trusted by the user's pip configuration.
  2. The attacker publishes or serves a malicious package version that satisfies the unconstrained dependency names.
  3. A user follows the documentation and runs:
    bash
    pip3 install python-docx olefile Pillow
    
  4. Pip resolves and installs the attacker-controlled artifact because no approved versions or hashes are enforced.
  5. Malicious code executes during installation or later when the affected dependency is imported by a toolkit script.
  6. The malicious code operates with the privileges of the user or automation account running pip or the scrip ...[truncated 689 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the unconstrained installation command with a reviewed, version-pinned dependency file.
  2. Generate a hash-locked requirements file containing all direct and transitive dependencies, for example with pip-compile --generate-hashes.
  3. Require hash verification during installation:
    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  4. Configure and document an explicitly trusted package index rather than relying on ambient pip configuration.
  5. Install dependencies inside an isolated virtual environment using a non-privileged account.
  6. Review dependency updates before changing pins and use automated dependency and vulnerability scanning.
  7. Preserve the reviewed lockfile and hashes in the project so installations are reproducible.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation only resizes or compresses filesystem images while the manifest claims it extracts text, tables, and images from Word documents, the skill's declared purpose materially misrepresents its real behavior. In a security context, this can conceal broader file-processing operations or cause unsafe delegation to a tool that has not been reviewed for the tasks users believe it performs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the implementation only resizes or compresses filesystem images while the manifest claims it extracts text, tables, and images from Word documents, the skill's declared purpose materially misrepresents its real behavior. In a security context, this can conceal broader file-processing operations or cause unsafe delegation to a tool that has not been reviewed for the tasks users believe it performs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation only resizes or compresses filesystem images while the manifest claims it extracts text, tables, and images from Word documents, the skill's declared purpose materially misrepresents its real behavior. In a security context, this can conceal broader file-processing operations or cause unsafe delegation to a tool that has not been reviewed for the tasks users believe it performs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation only resizes or compresses filesystem images while the manifest claims it extracts text, tables, and images from Word documents, the skill's declared purpose materially misrepresents its real behavior. In a security context, this can conceal broader file-processing operations or cause unsafe delegation to a tool that has not been reviewed for the tasks users believe it performs.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises commands that read input files and write extracted output, but the manifest does not declare any tool scope such as permissions or allowed-tools. This creates an authorization and review gap: an agent may be allowed to perform filesystem actions that are broader than users or platform policy expect, increasing the chance of unintended file access or modification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest says image handling includes deduplication and filtering for extracted images, which reasonably implies technical filtering such as duplicates or size thresholds. The module advertises filtering by document meaning using contextual inference about certificates, contracts, and test reports, which is a broader behavioral scope than simple extraction-oriented filtering.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script embeds locale-specific heading detection and later relies on Chinese keyword matching for categorization, effectively tailoring behavior to one language without user opt-in or explicit justification. Under the policy, forcing a specific language/locale without choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script writes extracted images and a context-rich manifest to disk, which can copy sensitive document content into a new location without any warning, confirmation, or privacy guardrail. In environments handling contracts, certificates, IDs, or regulated material, this increases the chance of unintended data exposure through local storage, backups, or downstream sharing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes extraction of text, tables, and images, with deduplication and filtering for extracted images. This code does not just extract images: it infers document semantics from nearby text, labels images as contracts, certificates, reports, credentials, personnel, and credit checks, and assigns review priority, which is a distinct analysis/triage behavior beyond plain extraction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

When --context is enabled, the script serializes paragraph text near images into image_manifest.json, potentially storing sensitive document excerpts alongside extracted files. That creates a secondary plaintext artifact containing business or personal data, which can be easier to overlook and leak than the original document.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

All category inference is based on Chinese terms such as 合同, 证书, and 检测报告, so the skill implicitly enforces a single-language workflow. Because the file does not offer a language choice or clearly justify that it is region-specific, this violates the language/locale policy.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a document extraction toolkit for pulling text, tables, and images from .docx/.doc files, but this script performs bulk image resizing, recompression, format conversion, and optional in-place overwrite of files. Those are post-processing and modification capabilities that go beyond the stated purpose of extraction and are not necessary to extract content from Word documents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script defaults to overwriting files in place when no output directory is supplied, with no confirmation, dry-run, or backup behavior. In a document-processing skill, that can silently destroy original extracted images or source artifacts, especially in automated pipelines where arguments are generated programmatically.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The module docstring frames the behavior as resizing images to a maximum dimension, but the implementation also recompresses images, saves non-PNG inputs as JPEG, and converts some PNGs to JPEG. That documentation is not just incomplete about minor details; it omits a material content-changing behavior that can alter format and fidelity beyond simple resizing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.