T08 · Insecure Dependencies
- Location
SKILL.md:18- Finding
Unpinned Third-Party Dependencies Permit Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward local PDF splitter for A3 exam papers, with ordinary file-writing and dependency risks users should understand before use.
Install only in an environment where you trust PyPI dependency resolution, and use it on PDFs you trust or that are reasonably sized. Confirm the input and output paths before running, choose a new output filename to avoid overwriting files, and avoid feeding it very large or untrusted PDFs.
SKILL.md:18Unpinned Third-Party Dependencies Permit Supply-Chain Risk
scripts/split_a3_smart.py:9Unbounded PDF Rendering and Image Retention Can Exhaust Memory
All user-facing instructions and trigger phrases are presented only in Chinese, which can constitute a language policy issue if the skill is expected to be generally usable without forcing a specific language. There is no indication that the skill is region-specific or that users can opt into another language.
The trigger conditions include broad phrases such as “PDF切分” and “试卷打印,” which can overlap with ordinary user requests and cause the skill to be invoked when the user did not specifically intend this tool. Because the skill performs file processing and writes a new PDF to a user-specified path, accidental invocation can lead to unintended file creation or modification workflows.
The markdown lists several natural-language trigger examples for invoking the skill, but it does not clearly define the exact trigger scope, required context, or any negative examples. Phrases like “拆分这个试卷PDF” and the generic invocation pattern in the usage example could overlap with ordinary requests unless the surrounding system already constrains activation tightly.
This markdown file instructs users to provide an output PDF path for the tool, which implies a file write operation. While the notes mention write permission, they do not clearly disclose the user-impacting behavior that the tool will generate or potentially replace a file at that location.
The usage instructions say to obtain input and output paths and run processing, but they do not clearly warn that the skill will generate and write a new PDF file to the specified output location. In an agent setting, insufficient disclosure around file-writing behavior increases the risk of surprising users, overwriting expected destinations, or causing unintended persistence of processed documents.
No suspicious patterns detected.