Back to skill

Security audit

Pdf Power

Security checks for vulnerabilities and agentic risk

Overview

This PDF utility skill is coherent and disclosed, with a normal but imperfect dependency-installation risk.

Install in an isolated environment when possible, and consider pinning reviewed versions of pypdf, PyMuPDF, and Pillow before first use. Avoid giving it sensitive PDFs unless you are comfortable with the local agent and installed libraries processing those files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned Third-Party Dependencies Installed at Runtime

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17–21
Vulnerability Type: Unpinned runtime dependency installation
Risk Level: Medium

Vulnerable Code:

markdown
The skill uses Python with `pypdf` + `PyMuPDF` (fitz). Install on first use:

```bash
pip install pypdf PyMuPDF Pillow
text

### Technical Analysis

The skill instructs the agent to install `pypdf`, `PyMuPDF`, and `Pillow` without fixed versions or cryptographic hashes. Consequently, the exact code installed can vary between executions. Dependency resolution may retrieve a newly published, compromised, or otherwise unsafe direct or transitive dependency.

Python package installation can execute package build and installation logic with the privileges of the agent process. Although the reviewed project does not contain malicious executable code and does not explicitly select an unofficial package source, the unpinned installation process creates a supply-chain exposure.

### Attack Path

1. An attacker compromises one of the named packages, its distribution account, or a transitive dependency.
2. The attacker publishes a malicious release that remains compatible with the unconstrained package requirement.
3. On first use, the agent follows the instruction and runs `pip install pypdf PyMuPDF Pillow`.
4. `pip` resolves and downloads the attacker-controlled release.
5. Malicious code executes during package installation, import, or subsequent PDF processing with the permissions of the agent process.

### Impact Assessment

Successful exploitation could permit arbitrary code execution under the agent's operating-system account. The resulting access could include reading or modifying PDFs and other files accessible to that account, tampering with generated documents, accessing available process credentials or environment variables, and making network requests where permitted.

The maximum scope is limited by the privileges and isol
...[truncated 211 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to an explicitly reviewed version in a requirements or lock file.
  2. Pin and review transitive dependencies so dependency resolution is reproducible.
  3. Record and verify package hashes, for example by installing with pip install --require-hashes -r requirements.txt.
  4. Explicitly use the approved official or organization-controlled package index and disable unexpected fallback indexes.
  5. Install dependencies inside an isolated, least-privilege virtual environment or sandbox rather than the agent's global Python environment.
  6. Prefer organization-approved, preinstalled packages so skill invocation does not perform runtime installation.
  7. Apply dependency vulnerability scanning and periodically review pinned versions before controlled updates.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.