Back to skill

Security audit

PDF 工具箱

Security checks for vulnerabilities and agentic risk

Overview

This is a local PDF-processing skill with some overstated or missing advertised features and ordinary file-handling cautions, but no evidence of hidden data access, persistence, or malicious behavior.

Install only if the Chinese-language interface is acceptable and you need the included local PDF operations. Use copies of important PDFs, choose output paths that do not overwrite originals, avoid processing confidential documents in untrusted environments, and install pypdf from a trusted pinned dependency source.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
scripts/merge_pdf.py:12
Finding

Unpinned Third-Party Dependency Installation Guidance

Content
View full analysis
Remediation
View remediation
``` 2. Generate and verify cryptographic hashes for all permitted artifacts. Install with hash enforcement: ```bash python -m pip install --require-hashes -r requirements.txt ``` 3. Use a lock file generated through a controlled dependency-management process and commit it to the project. 4. Document an approved package index or internal mirror rather than relying on arbitrary user-level pip configuration. 5. Replace the generic installation message with instructions that refer to the project's reviewed dependency file: ```python "install": "python -m pip install --require-hashes -r requirements.txt" ``` 6. Regularly scan pinned dependencies for known vulnerabilities and update them through a reviewed process. 7. Run installation and PDF processing under a non-privileged account with access limited to the required input and output files. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

代码的实际行为与“PDF 工具箱”这一宽泛、多功能描述不一致。该代码块只实现了 PDF 压缩功能,主要通过调用 Ghostscript 或使用 pypdf 进行简化压缩。虽然“压缩 PDF 大小”属于声明范围的一部分,但声明给人的能力范围明显更广,而此代码并未体现其他核心功能。未发现明显越权或未声明的敏感行为;调用 Ghostscript 属于实现压缩的正常依赖,不构成额外能力问题。整体上这是描述过宽、实现过窄的能力不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

该代码的实际主功能是“PDF 拆分工具”,与文件头注释和实现都一致:使用 pypdf 读取输入 PDF,并根据 --pages 参数按页拆分为多个文件,或将指定页提取到一个新 PDF。它没有执行任何超出声明的敏感或未声明能力,也没有异常权限或触发器问题。但声明将该技能描述为覆盖多种 PDF 处理能力的完整工具箱,这会让人预期存在合并、旋转、压缩、转换、文字提取、水印等操作;而当前代码块并未体现这些能力。因此属于描述显著宽于实际行为的能力不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises shell execution and file-writing behavior through example commands, but it does not declare any tool scope such as allowed-tools or permissions. That creates an authorization and least-privilege gap: an agent may invoke shell/file operations more broadly than users or platform policy expect. In a file-processing skill, this is materially risky because commands modify files and could be repurposed against unintended paths or files if the surrounding agent is permissive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill encourages text extraction and conversion from PDFs without warning that PDFs may contain sensitive personal, financial, legal, or proprietary information. Users may unknowingly process confidential content, increasing the chance of unintended disclosure, insecure handling of extracted text/images, or accidental sharing of derived outputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documents multiple file-modifying and batch operations but does not warn users about overwrite, corruption, irreversible transformation, or propagating changes across many files. In context, batch shell loops and commands that rewrite PDFs can cause widespread accidental data loss or alter authoritative documents without adequate user awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's natural-language description and all user-facing messages are exclusively in Chinese, with no indication that the user can choose another language. That creates a language/locale policy concern because the skill effectively enforces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/compress_pdf.py (reported line 44)May include surrounding context.

python
# 检查是否有 ghostscript
        has_ghostscript = False
        try:
            subprocess.run(["gs", "--version"], capture_output=True, check=True)
            has_ghostscript = True
        except (subprocess.CalledProcessError, FileNotFoundError):
            pass

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/compress_pdf.py (reported line 71)May include surrounding context.

python
input_file
            ]
            
            result = subprocess.run(cmd, capture_output=True, text=True)
            
            if os.path.exists(output_file):
                compressed_size = os.path.getsize(output_file)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script writes directly to the user-supplied output path without checking whether the file already exists or whether the output path is the same as the input path. This can silently overwrite existing files or corrupt user data, which is especially risky in a file-manipulation skill where paths are likely provided dynamically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language interface and messages are entirely in Chinese, beginning with the module description and continuing through user-facing outputs. Under the policy, forcing a specific language without opt-in or justification is a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains natural-language strings that require users to understand Chinese to use the tool, including the module docstring and later CLI messages. Under the policy, forcing a specific language without opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language instructions and examples are fully localized to Chinese, which can impose a language constraint on users without explicit opt-in. The file does not indicate that the skill is region-specific or provide an alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code's docstrings, usage text, error messages, and success messages are all presented only in Chinese. Under the stated policy, a skill should not force a specific language without user opt-in unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.