Back to skill

Security audit

convert2docx

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local document-to-Word converter with a few operational cautions but no evidence of hidden, destructive, or data-exfiltrating behavior.

Install only if you are comfortable running a local PowerShell-based converter. Review the bundled scripts first, install Pandoc from its official source, provide only documents you intend to convert, and be aware that config.ini stores local paths to Pandoc and your reference.docx template.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/convert2docx.ps1 (reported line 1)May include surrounding context.

text
# convert2docx.ps1
# 把各种文档格式转成 .docx,并套用用户指定的 reference.docx
# 本脚本不提供默认 reference.docx,必须由用户自己准备

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The WorkBuddy trigger phrase is very broad: saying '把 xx.md 转成 Word,用我的 reference.docx' implies the skill may activate on generic document-conversion requests without clear scope limits or exclusion conditions. In an agent environment, overly broad triggers can cause unintended invocation on user content or nearby requests, leading to misrouting, incorrect file handling, or accidental processing of sensitive documents.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation text includes broad natural-language triggers such as "把 XX 转成 Word" and "批量转 docx" without clear boundaries, exclusions, or a constrained execution context. These phrases are common enough in normal conversation that they could cause unintended activation of the skill when a user is only discussing a task rather than explicitly invoking this tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill guidance is written in Chinese and includes locale-specific instructions such as '中文用户注意', but it does not indicate that the language choice is optional or that the skill is intentionally limited to a Chinese-speaking audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The batch file invokes PowerShell with -ExecutionPolicy Bypass, which disables a native safety control and allows the companion script to run even where local policy would normally restrict script execution. In a drag-and-drop document conversion skill, this increases risk because users may launch it casually and the bypass reduces friction for executing any malicious or tampered PowerShell content in the same directory.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

整个 README 以中文编写,并在 WorkBuddy 示例中默认使用中文指令,但没有说明是否支持其他语言或允许用户选择语言。按组织语言/locale 策略,若技能暗含固定语言而未提供选择或正当限定,可能构成自然语言策略违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file presents all user-facing instructions exclusively in Chinese, which can violate a language/locale policy when no user opt-in or alternative language is offered. There is no indication that this skill is intentionally limited to a Chinese-speaking audience or region-specific use case.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.