Back to skill

Security audit

md-2-pdf

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Markdown-to-PDF converter with ordinary file read/write behavior for that purpose, but users should be aware it installs an unpinned PDF library at runtime.

Install only if you are comfortable running a local uv Python script that reads the Markdown file and any referenced local image paths and writes a PDF. For sensitive environments, pin or lock the reportlab dependency and run the converter with access limited to the intended input and output directory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/md-to-pdf.py:1
Finding

Unpinned Runtime Dependency Permits Supply-Chain Substitution

Content
View full analysis
=3.10" # dependencies = [ # "reportlab", # ] # /// ``` The documented invocation in `SKILL.md`, lines 14–23, executes the script through `uv`: ```bash uv run scripts/md-to-pdf.py input.md uv run scripts/md-to-pdf.py input.md -o output.pdf uv run scripts/md-to-pdf.py input.md --output my-report.pdf uv run scripts/md-to-pdf.py input.md -v ``` ### Technical Analysis The inline dependency declaration specifies `reportlab` without an exact version, lock file, or integrity hash. When the documented `uv run` command is used, `uv` may resolve and install whichever compatible package version is available from the configured package index. Consequently, the effective executable code is not limited to the reviewed project. It also includes mutable third-party package code selected at runtime. A compromised package release, package index, mirror, or resolver configuration could substitute hostile dependency code without requiring a modification to this repository. The project contains no evidence that the current `reportlab` package is malicious. The risk arises from the absence of controls that make dependency resolution reproducible and verify the integrity of downloaded artifacts. ### Attack Path 1. An attacker compromises a compatible `reportlab` release, a configured Python package index or mirror, or the victim's dependency-resolution configuration. 2. The attacker causes a malicious package artifact or release to satisfy the unconstrained `reportlab` dependency. 3. A user follows the documented command and runs the script with `uv run`. 4. `uv` resolves and installs the attacker-controlled dependency when no previously trusted locked environment prevents resolution. 5. Python imp ...[truncated 1009 chars]
Remediation
View remediation
", # ] ``` 2. Generate and commit a `uv.lock` file that records the complete resolved dependency graph. 3. Require locked or frozen dependency installation in documented and automated execution workflows so dependency drift causes failure instead of silent re-resolution. 4. Verify package artifacts with cryptographic hashes where the selected workflow supports them. 5. Retrieve dependencies only from an approved package index or trusted internal mirror, and prevent fallback to untrusted sources. 6. Add automated dependency vulnerability and provenance scanning to the release process. 7. Periodically update the pinned version through a controlled process that includes source review, vulnerability review, testing, and lock-file regeneration. 8. Run the converter with least privilege and restrict filesystem, credential, process, and network access to reduce the impact of a compromised dependency. ]]>
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill invokes a local script against user-supplied markdown input, which necessarily reads files, but the manifest does not declare any tool scope or permissions. This creates an authorization and transparency gap: a host may not be able to properly constrain or communicate the file access the skill requires, increasing the risk of unintended file reads if the input path is manipulated or the skill is run in a broader workspace.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.