Back to skill

Security audit

自动从中间空白处切割A3试卷a3-pdf-splitter

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward local PDF splitter for A3 exam papers, with ordinary file-writing and dependency risks users should understand before use.

Install only in an environment where you trust PyPI dependency resolution, and use it on PDFs you trust or that are reasonably sized. Confirm the input and output paths before running, choose a new output filename to avoid overwriting files, and avoid feeding it very large or untrusted PDFs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

Unpinned Third-Party Dependencies Permit Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/split_a3_smart.py:9
Finding

Unbounded PDF Rendering and Image Retention Can Exhaust Memory

Content
View full analysis
height: split_x = find_best_split_position(img, is_horizontal=True) left_img = img.crop((0, 0, split_x, img.height)) output_images.append(left_img) right_img = img.crop((split_x, 0, img.width, img.height)) output_images.append(right_img) else: split_y = find_best_split_position(img, is_horizontal=False) top_img = img.crop((0, 0, img.width, split_y)) output_images.append(top_img) bottom_img = img.crop((0, split_y, img.width, img.height)) output_images.append(bottom_img) ``` ### Technical Analysis The script accepts a PDF without enforcing limits on its file size, page count, page dimensions, rendered pixel count, or aggregate processing cost. Every page is rendered at a fixed 400 DPI, which can produce large raster images. The grayscale image is then expanded into a Python list through `list(gray_img.getdata())`. A Python list of pixel objects can consume substantially more memory than the underlying packed image buffer. In addition, both cropped images from every processed page are appended to `output_images` and retained until the entire document is saved. Memory consumption therefore grows with the total number and dimensions of pages rather than being bounded to one page. ### Attack Path 1. An attacker or untrusted user supplies ...[truncated 1057 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

All user-facing instructions and trigger phrases are presented only in Chinese, which can constitute a language policy issue if the skill is expected to be generally usable without forcing a specific language. There is no indication that the skill is region-specific or that users can opt into another language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions include broad phrases such as “PDF切分” and “试卷打印,” which can overlap with ordinary user requests and cause the skill to be invoked when the user did not specifically intend this tool. Because the skill performs file processing and writes a new PDF to a user-specified path, accidental invocation can lead to unintended file creation or modification workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The markdown lists several natural-language trigger examples for invoking the skill, but it does not clearly define the exact trigger scope, required context, or any negative examples. Phrases like “拆分这个试卷PDF” and the generic invocation pattern in the usage example could overlap with ordinary requests unless the surrounding system already constrains activation tightly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file instructs users to provide an output PDF path for the tool, which implies a file write operation. While the notes mention write permission, they do not clearly disclose the user-impacting behavior that the tool will generate or potentially replace a file at that location.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The usage instructions say to obtain input and output paths and run processing, but they do not clearly warn that the skill will generate and write a new PDF file to the specified output location. In an agent setting, insufficient disclosure around file-writing behavior increases the risk of surprising users, overwriting expected destinations, or causing unintended persistence of processed documents.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.