Back to skill

Security audit

论文阅读助手

Security checks for vulnerabilities and agentic risk

Overview

This PDF-reading skill is mostly purpose-aligned, but it automatically installs unpinned Python packages and persistently caches extracted paper text in the user's home directory.

Review this skill carefully before installing. It is not backed by evidence of exfiltration or destructive behavior, but it can modify your Python environment by installing packages and can retain extracted paper text in a persistent home-directory cache. Avoid using it on confidential, unpublished, or proprietary PDFs unless you are comfortable with local caching and can manage or clear the cache yourself.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/read_paper_main.py:126
Finding

Automatic Installation of Unpinned Third-Party Dependencies

Content
View full analysis

Vulnerability Details

File Location: scripts/read_paper_main.py, lines 126-129 and 151-155
Vulnerability Type: Supply-chain exposure through runtime package installation
Risk Level: Medium

Vulnerable Code:

python
subprocess.check_call([
    sys.executable, '-m', 'pip', 'install', package_name,
    '-q', '--disable-pip-version-check'
])

The package names passed to this installation routine are:

python
libraries = [
    ('pymupdf', 'fitz'),           # PyMuPDF
    ('pdfplumber', 'pdfplumber'),  # pdfplumber
    ('pypdf', 'pypdf'),            # pypdf
]

Technical Analysis

When a required PDF library is unavailable, the skill automatically invokes pip to download and install it. The dependencies have no fixed versions, integrity hashes, trusted-index restrictions, or lock-file controls. The effective code installed during execution can therefore change independently of the reviewed skill package.

Python package installation may execute package build logic and subsequently imports the installed package into the skill process. As a result, compromise of a package release, configured package repository, dependency resolution path, or network distribution channel could introduce arbitrary code into the agent environment.

This is not evidence that the named packages are malicious. The vulnerability is the mutable and unverified runtime dependency installation process.

Attack Path

  1. The skill runs in an environment where one or more PDF-processing libraries are missing.
  2. ensure_package_installed invokes the environment's configured pip client.
  3. Pip resolves the package from its configured package index without enforcing a reviewed version or package hash.
  4. An attacker who has compromised the relevant package release, index, mirror, or dependency-resolution configuration supplies malicious package content.
  5. Installation or subsequent import executes the ma ...[truncated 623 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove automatic runtime installation and declare dependencies through a standard project manifest.
  • Pin every direct and transitive dependency to a reviewed version in a lock file.
  • Require package hashes, such as with pip's --require-hashes, to verify artifact integrity.
  • Install dependencies during a controlled deployment or build stage rather than when processing a user document.
  • Restrict package resolution to an approved repository or internal mirror.
  • Run dependency scanning and signature or provenance verification where supported.
  • If runtime installation is unavoidable, obtain explicit user consent, use an isolated virtual environment, enforce exact versions and hashes, and avoid importing packages until their integrity has been validated.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/read_paper_main.py:51
Finding

Cache Key Collision Can Return Content from an Unrelated PDF

Content
View full analysis

Vulnerability Details

File Location: scripts/read_paper_main.py, lines 51-69
Vulnerability Type: Weak cache identity and cross-document cache confusion
Risk Level: Medium

Vulnerable Code:

python
def _get_fingerprint(self, pdf_path):
    try:
        stat = os.stat(pdf_path)
        content = f"{stat.st_size}_{stat.st_mtime}"
        return hashlib.md5(content.encode()).hexdigest()[:16]
    except:
        return None

def get(self, pdf_path):
    fingerprint = self._get_fingerprint(pdf_path)
    if not fingerprint or fingerprint not in self.index:
        return None
    
    cache_file = self.cache_dir / f"{fingerprint}.json"
    if cache_file.exists():
        try:
            with open(cache_file, 'r', encoding='utf-8') as f:
                return json.load(f)
        except:
            pass
    return None

Related cache-write logic at lines 71-85:

python
def set(self, pdf_path, data):
    fingerprint = self._get_fingerprint(pdf_path)
    if not fingerprint:
        return False
    
    cache_file = self.cache_dir / f"{fingerprint}.json"
    try:
        with open(cache_file, 'w', encoding='utf-8') as f:
            json.dump(data, f, ensure_ascii=False, indent=2)
    
        self.index[fingerprint] = {
            'path': str(pdf_path),
            'title': data.get('title', '')[:100],
            'cached_at': time.time()
        }
        self._save_index()
        return True
    except:
        return False

Technical Analysis

The cache fingerprint is derived only from the PDF's byte size and modification timestamp. It does not incorporate the file contents or canonical path. Two distinct PDFs with matching size and modification time therefore produce the same truncated MD5 cache identifier.

On a cache hit, the implementation loads and returns the existing JSON entry without verifying that its source path, ...[truncated 1783 chars]

Remediation
View remediation

Remediation Suggestions

  • Compute the cache key from the complete PDF contents using SHA-256 or another modern cryptographic hash.
  • Optionally include the canonical source path and extraction-tool version when cache entries are intended to remain path-specific.
  • Store the full content digest inside each cache record and verify it before returning a cache hit.
  • Use atomic writes and restrictive owner-only permissions for the cache directory and files.
  • Separate caches by user or trust domain where the application serves multiple users.
  • Avoid caching sensitive extracted content by default, or provide explicit cache opt-out, expiration, inspection, and deletion controls.
  • Invalidate existing entries created with the size-and-timestamp scheme after deploying the corrected implementation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented purpose understates several sensitive behaviors: automatic pip installation, persistent caching in the user home directory, and reliance on downstream AI for report generation rather than directly producing the final report. Hidden environment modification and undeclared persistence are dangerous because they can change the local system state, introduce supply-chain risk, and retain sensitive paper contents without clear user consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Auto-installing Python packages at runtime is unjustified for the stated skill purpose and significantly increases attack surface. In the context of a document-analysis skill, this is more dangerous because users reasonably expect local file processing, not environment mutation and execution of package installer code fetched from external sources.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire example, including usage, triggers, and report output, is presented only in Chinese, implying a fixed language/locale behavior. There is no indication that users can choose another language or that the Chinese-only constraint is intentional and justified for a region-specific skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language triggers shown here are very broad generic phrases like '帮我读这篇论文' and '分析这篇论文', which can overlap with ordinary conversation and cause the skill to activate unexpectedly. In a skill that reads local files or fetches remote URLs, accidental activation can lead to unintended document access, network retrieval, or report generation without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example flow shows the assistant automatically generating and saving a report to disk, then only informing the user afterward. Writing files without an upfront warning or confirmation can create unintended data persistence, leak sensitive paper contents into shared/workspace directories, or overwrite user expectations about what actions analysis will perform.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises capabilities that imply file reads, file writes, and shell execution, but it does not declare any explicit tool scope or permissions. This creates an authority mismatch where a user or orchestrator cannot easily understand or constrain what the skill may access, increasing the chance of unintended filesystem changes or command execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The description explicitly states that the skill generates a '全中文阅读报告', which imposes a specific language on output. The file does not offer user opt-in or explain a justified region-specific requirement, so this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Manifest 与简介将该技能描述为“论文阅读报告生成器”,但工作流程明确写的是“Python提取PDF内容→保存为结构化文件→AI读取文件→AI直接生成中文报告”。这表明技能本身实现的核心职责是内容提取与落盘,而最终中文报告生成依赖外部 AI,而非该技能代码自身完成。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The introduction says the tool generates a Chinese reading report directly, reinforcing a fixed language requirement. Because no alternative language option or user choice is described anywhere in the skill documentation, this appears to violate the language/locale policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatic installation of PDF libraries can modify the local environment and may download packages from external sources, but the documentation does not clearly warn users about these side effects. This is dangerous because it introduces supply-chain exposure, unexpected network activity, and possible breakage of the user's Python environment without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill writes extracted paper content and generated reports to disk but does not clearly warn users that sensitive, confidential, or copyrighted document contents will be persisted locally. This can expose data to other local users, backups, indexing tools, or unintended sharing, especially when the input PDFs are proprietary or unpublished.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Caching extracted PDF contents for 30 days creates a clear data-retention risk, especially for sensitive, embargoed, or proprietary papers. Without a prominent warning and user control, users may unknowingly leave document contents stored in a predictable location long after analysis is complete.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/read_paper_main.py (reported line 124)May include surrounding context.

python
import_name = package_name
    
    try:
        __import__(import_name)
        return True
    except ImportError:
        print(f"  未检测到 {package_name},正在安装...", end=' ')

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/read_paper_main.py (reported line 137)May include surrounding context.

python
import_name = package_name
    
    try:
        __import__(import_name)
        return True
    except ImportError:
        print(f"  未检测到 {package_name},正在安装...", end=' ')

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

The script invokes pip at runtime to install packages automatically, which introduces a software supply chain risk and permits network-retrieved code to be executed in the user's environment. Even though the package names are hardcoded, this behavior expands the skill's trust boundary far beyond PDF parsing and can lead to arbitrary code execution through compromised packages, indexes, mirrors, or installation hooks.

Content

Scanner excerpt · scripts/read_paper_main.py (reported line 130)May include surrounding context.

python
print(f"  未检测到 {package_name},正在安装...", end=' ')
        try:
            import subprocess
            subprocess.check_call([
                sys.executable, '-m', 'pip', 'install', package_name,
                '-q', '--disable-pip-version-check'
            ])

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a complete '论文阅读报告生成器' that extracts PDF content and generates a fully Chinese reading report. However, the main function explicitly states it is '方案B:提取内容供AI直接分析', writes an extracted-content text file, and the CLI instructs the user to provide that file to an AI assistant for the actual report. This is a semantic mismatch between the advertised end-to-end report generation and the implemented behavior in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The user-facing instruction says to send the extracted file to an AI assistant so it can generate a complete Chinese reading report. This imposes a specific output language in natural-language guidance, and the file does not offer the user an opt-in choice or alternative locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring explicitly says the extracted paper content is for AI to directly generate Chinese reports. This is a natural-language locale policy constraint, and the file does not mention any user-selectable language option or justification for requiring Chinese output.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description emphasizes extracting structured content from PDFs and generating a Chinese reading report, but this file implements persistent filesystem output via save_report(). Writing a report file is an additional behavior beyond pure extraction/analysis and is not stated in the manifest text shown here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

L34-L37 说明 WorkBuddy 自动完成的是提取文件后由 AI 直接生成报告,而 L136-L145 又将“阅读报告文件”列为该技能运行后会生成的输出文件。对同一技能而言,这两处表述对“是谁生成并输出报告文件”给出了不一致的意图描述,容易误导使用者对技能实际行为的理解。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown template presents all headings and instructional text exclusively in Chinese, which imposes a specific language on users without any opt-in or alternative. Under the natural-language policy rule, forcing a language without user choice can be a locale/language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.