Back to skill

Security audit

Links to PDFs

Security checks for vulnerabilities and agentic risk

Overview

The skill is a document scraper with coherent goals, but it asks users to install an unverified global CLI and handles credentials, persisted sessions, local document deletion, and external Claude page analysis with insufficient scoping and warnings.

Install only if you trust the docs-scraper npm package and its publisher. Avoid entering real passwords in command-line arguments, clear saved profiles when finished, treat PDFs under ~/.docs-scraper/output as sensitive, and avoid the LLM fallback for private or authenticated pages unless you are comfortable sending page HTML to Claude.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:12
Finding

Unpinned Third-Party Package Installed Globally

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:54
Finding

Passwords Exposed Through Command-Line Arguments

Content
View full analysis
-D email=user@example.com -D password=1234 ``` ### Technical Analysis The documented authentication mechanism places plaintext passwords directly in command-line arguments. Depending on the operating system and shell configuration, these secrets may be exposed through: - Persistent shell history. - Process listings or process metadata available to local users and monitoring agents. - Terminal session recording. - Command auditing and endpoint telemetry. - Debug ou ...[truncated 1943 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation describes profile-based authenticated scraping but does not clearly warn that session cookies are persisted and that downloaded files are stored locally, which can expose sensitive documents or reusable authentication state to other local users, backups, or endpoint compromise. This is especially important in a scraping tool handling protected Notion and DocSend content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation states that the daemon automatically cleans up files older than 1 hour and that docs-scraper cleanup deletes all PDFs, but it does not warn users that these are destructive operations. Since deletion is irreversible from the user's perspective, the skill description should clearly disclose this behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented LLM fallback materially expands the skill's behavior from document-to-PDF conversion into arbitrary webpage analysis with external transmission of page content to Claude. Because it also detects login forms and dynamic credential fields, users could unknowingly send sensitive page HTML and authentication context to a third party, which creates privacy, credential-handling, and scope-creep risk beyond the stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Requiring an ANTHROPIC_API_KEY for page analysis indicates outbound sharing of webpage data with an external service that is not clearly necessary for a scraper whose advertised purpose is local PDF generation. This mismatch can mislead operators about data flows and increases the chance that sensitive internal documents, login pages, or metadata are processed by a third party without clear consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.