Back to skill

Security audit

wps_office_auto_skill

Security checks for vulnerabilities and agentic risk

Overview

This local office-automation skill is mostly purpose-aligned, but it needs Review because it requests broad file access while processing sensitive office files with vulnerable dependencies and weak input limits.

Install only if you are comfortable granting broad filesystem access to a local office-document parser. Avoid running it on highly confidential or untrusted files until dependencies are updated, input/file-size limits are added, and file output/overwrite behavior is documented. There is no evidence of exfiltration or persistence, but malformed PDFs, spreadsheets, or images could cause denial of service or increase parser exploit risk.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
main.py:319
Finding

Unbounded In-Memory Processing of Untrusted Office Files

Content
View full analysis
Dict[str, Any]: """处理数据清洗""" data = params.get("data") if isinstance(data, str): data = base64.b64decode(data) request = DataCleaningRequest( data=data, remove_duplicates=params.get("remove_duplicates", True), handle_missing=params.get("handle_missing", "mean"), remove_outliers=params.get("remove_outliers", True), outlier_method=params.get("outlier_method", "iqr"), ) result = await self.sheet_processor.clean_data(request) ``` The same unrestricted decoding pattern is present in the spreadsheet analysis, chart-generation, and PDF handlers. PDF merge also decodes every supplied file into a list before parsing: ```python pdf_files = [ base64.b64decode(file_data) for file_data in params.get("files", []) ] ``` The downstream processors parse XLSX and PDF content synchronously and in memory. XLSX files are ZIP-based containers, while PDFs can contain highly compressed or parser-expensive structures. Consequently, a comparatively small request can cause disproportionate CPU or memory consumption. The configured maximum execution time does not itself establish memory, decoded-size, page-count, or archive-expansion limits. ### Attack Path 1. An attacker invokes a spreadsheet or PDF operation exposed by `execute()`. 2. The attacker supplies an extremely large Base64 value, numerous PDF merge inputs, or a compact but parser-expensive document. 3. The Skill decodes the co ...[truncated 665 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
modules/spreadsheet.py:260
Finding

Spreadsheet Formula Injection in Generated Workbooks

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
skill.yaml:42
Finding

Broad Filesystem Permission Exceeds the Skill's Runtime Requirements

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
DEPLOYMENT.md:75
Finding

Unpinned Executable Dependencies in the Deployment Pipeline

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (48)

Known Vulnerable Dependency: Pillow==10.0.1 — 16 advisory(ies): CVE-2023-50447 (Arbitrary Code Execution in Pillow); CVE-2024-28219 (Pillow buffer overflow vulnerability); CVE-2026-55379 (Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()`) +13 more

Critical
Category
Supply Chain
Confidence
94% confidence
Finding

Pillow==10.0.1 is associated with multiple published vulnerabilities, including issues that can lead to memory corruption, denial of service, and potentially arbitrary code execution when parsing crafted image files. Because this skill depends on document-processing libraries and likely handles user-supplied files or embedded images, the attack surface is materially increased and exploitation could occur through normal workflow inputs.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 164)May include surrounding context.

  1. 删除环境变量文件

    bash
    rm .env .env.example
    
  2. 更新依赖

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · modules/presentation.py (reported line 104)May include surrounding context.

python
prompt += f"关键要点:{', '.join(request.key_points)}\n"
            
        prompt += "\n请生成每张幻灯片的标题和内容要点。"
        return prompt
        
    def _generate_template_outline(self, request: OutlineRequest) -> PresentationOutline:
        """生成模板大纲"""

Known Vulnerable Dependency: PyPDF2==3.0.1 — 2 advisory(ies): CVE-2023-36464 (pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a chara); CVE-2023-36464 (pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a chara)

High
Category
Supply Chain
Confidence
97% confidence
Finding

PyPDF2==3.0.1 is flagged with a known denial-of-service issue (CVE-2023-36464) involving malformed PDF parsing that can trigger an infinite loop. In a skill that processes document files, this dependency is plausibly exposed to untrusted input, making parser hangs and resource exhaustion a realistic risk rather than a purely theoretical one.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

All natural-language instructions in this file are Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking region or audience. This matches the language/locale policy concern for files that force a specific language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill processes potentially sensitive office documents, contracts, spreadsheets, and PDFs, yet the README does not tell users what data may be logged, cached, stored temporarily, or exposed through generated outputs. Even though it claims local processing, absence of a clear privacy warning can cause users to submit confidential material without understanding retention and handling risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README advertises file-destructive operations such as PDF merge/split and spreadsheet cleaning but does not warn about overwriting source files, irreversible transformations, or the need to keep backups. In an automation skill, users may assume safe default handling; if the implementation writes in place or replaces files, this omission increases the risk of accidental data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises PDF merge/split/watermark batch operations but does not warn users that these actions can overwrite files, alter document structure, or cause irreversible changes when run at scale. In an office automation context, users may apply these operations to sensitive or important business documents, so missing safety guidance increases the risk of accidental data loss or unintended modification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

All user-facing natural-language strings, example actions, and outputs are written exclusively in Chinese, with no indication that users may choose another language. This can violate language/locale policy when a skill implicitly enforces a specific language without opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Docstrings, console messages, and action labels throughout the file are presented in Chinese only, which imposes a specific language on users without any opt-in or explanation. Under the policy, language constraints should either be optional or clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code reads a local PDF, base64-encodes its contents, and passes the full document data to execute(), which may involve processing outside the local function boundary. While the file includes success prints after processing, it does not provide any prior disclosure, prompt, or comment warning that document contents are being sent for processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This example sends the base64-encoded contents of tables.pdf to execute() for processing. The code does not include a prior disclosure, confirmation, or warning that document contents are being sent for processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The function sends the contents of document.pdf to execute() for text extraction. No preceding warning or disclosure informs the user that the document's contents are being transmitted/processed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The example sends report.pdf content to execute() to produce a summary. There is no prior disclosure or confirmation that document contents are being sent for processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The function sends paper.pdf content to execute() for key-point extraction. It lacks any prior user disclosure that document contents are being processed/transmitted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This example base64-encodes multiple local PDFs and sends them to execute() for merging. The code does not disclose beforehand that full file contents are being transmitted/processed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example sends the contents of large_document.pdf to execute() for splitting. No prior warning or disclosure explains that document contents are being transmitted/processed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The function sends document.pdf content to execute() for watermarking. It does not provide a prior warning or explanatory note that the file contents are being sent for processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python example file uses Chinese exclusively in user-facing docstrings, action names, printed messages, filenames, and data labels. That creates a locale/language constraint in the skill experience without offering the user a language choice or documenting that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring and all user-facing messages are written exclusively in Chinese, indicating the skill is designed around a single language without any visible opt-in or alternative locale handling. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and user-facing descriptions are written exclusively in Chinese, and the file does not indicate that the skill is region-specific or that users can opt into this locale. Under the policy rule, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file uses Chinese-only natural-language descriptions and log/user-facing text throughout the module, starting with the module docstring. The policy specifically calls for flagging language or locale constraints when the skill forces a specific language without user opt-in, and there is no indication of language selection or a justified region-specific scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring at L377 says this function creates a watermark page, and add_watermark relies on it to apply the supplied watermark_text. However, the implementation only sets color and font on a blank ReportLab canvas and saves it without drawing any text, so the returned page does not match the documented intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains natural-language documentation strings such as the module description and field descriptions exclusively in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s natural-language documentation is entirely in Chinese and provides no indication that users may choose another language or that the module is intended only for a Chinese-language or region-specific context. Under the policy, forcing a specific language without opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.