Back to skill

Security audit

PDF to Word Converter

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a disclosed local document converter, with notable but purpose-aligned risks from a proprietary SDK, first-run downloads, and local trial-use tracking.

Install this only if you are comfortable using ComPDF's proprietary SDK and allowing first-run downloads from ComPDF for a license file and a large AI model. For sensitive documents, run conversions in a restricted workspace, pin and review the SDK version, pre-stage verified license/model files when possible, and be aware the trial counter is stored in your home directory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/pdf-to-word-docx.py:136
Finding

Unpinned proprietary dependency and unverified runtime model loading

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:28-31; scripts/pdf-to-word-docx.py:136-140, 316-323, 331-357, and 534-544
Vulnerability Type: Third-party supply-chain integrity failure
Risk Level: Medium

The Skill instructs users to install a proprietary SDK without pinning an audited version or verifying the package hash:

bash
pip install ComPDFKitConversion

The script also downloads a model from a mutable remote location:

python
DOCUMENT_AI_MODEL_URL = "https://download.compdf.com/skills/model/documentai.model"
DOCUMENT_AI_MODEL_ENV = "COMPDF_DOCUMENT_AI_MODEL"
DOCUMENT_AI_MODEL_RETRY_DELAYS = (2, 5, 10)

LICENSE_URL = "https://download.compdf.com/skills/license/license.xml"
LICENSE_RETRY_DELAYS = (2, 5, 10)

The download function writes the remote response directly to a local file without verifying a cryptographic digest or digital signature:

python
def download_file(url: str, destination: Path, timeout: int = 120) -> None:
    destination.parent.mkdir(parents=True, exist_ok=True)
    with urllib.request.urlopen(url, timeout=timeout) as response, destination.open("wb") as output:
        while True:
            chunk = response.read(1024 * 1024)
            if not chunk:
                break
            output.write(chunk)

The only content validation performed on the downloaded model is a non-empty-file check:

python
def ensure_document_ai_model(scripts_dir: Path) -> Path:
    model_path = get_document_ai_model_path(scripts_dir)
    if model_path.is_file() and model_path.stat().st_size > 0:
        return model_path
    temp_path = model_path.with_suffix(model_path.suffix + ".part")
    last_error: Exception | None = None
    for attempt in range(len(DOCUMENT_AI_MODEL_RETRY_DELAYS) + 1):
        try:
            print(f"documentai.model not found, downloading from {DOCUMENT_AI_MODEL_URL}...", file=sys.stderr)
            if temp_p
...[truncated 5145 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin ComPDFKitConversion to a specifically reviewed version rather than using an unconstrained package name.
  2. Use a requirements or lock file containing cryptographic hashes, and install with hash enforcement, such as pip install --require-hashes -r requirements.txt.
  3. Obtain expected SHA-256 digests or digital signatures for documentai.model and license.xml through a separately authenticated release channel.
  4. Verify each downloaded artifact before renaming it into its final location. Delete it and fail closed if verification fails.
  5. Version model URLs or bind expected hashes to Skill releases so a previously audited Skill cannot silently receive a different artifact.
  6. Make automatic downloads opt-in. Provide an offline deployment mode in which administrators pre-stage verified dependencies and model files.
  7. Avoid placing mutable downloaded resources inside the installed Skill directory. Use a dedicated, permission-restricted cache directory and reject symbolic links or unexpected file types.
  8. Run conversion in a sandbox with only the required input and output paths mounted. Deny access to unrelated user files, credentials, and environment variables.
  9. Restrict outbound network access during conversion after verified dependencies have been provisioned.
  10. Document whether the proprietary SDK performs telemetry, online license checks, or document uploads, and provide a supported network-disabled mode where possible.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The manifest presents a narrowly scoped PDF-to-Word converter, but the documented behavior is materially broader: it supports many formats, image inputs, automatic remote downloads, and local trial-usage tracking. This mismatch can mislead users and orchestrators about the skill's real authority and side effects, which is especially risky in agent systems that rely on metadata for safe routing and consent.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
- The entry point is `SKILL.md`; helper scripts are placed in `scripts/`.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documents capabilities that include environment access, file reads/writes, and network activity, but it does not declare any explicit tool scope or permission boundaries. In an agent environment, this increases the chance the skill will be invoked with broader privileges than users expect, especially since it can download files and write to local paths.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is branded and described as a PDF-to-Word/DOCX tool, but the content shows a general-purpose document conversion wrapper with substantially broader functionality. Even without malicious intent, this is dangerous because users and policy systems may grant trust appropriate for a narrow converter while the skill can perform a wider range of conversions and process additional input types.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill performs automatic network downloads of a license file and a large model file from third-party servers, yet this capability is not clearly justified or constrained by the manifest's stated purpose. Automatic retrieval of executable-adjacent resources introduces supply-chain, privacy, and integrity risks, particularly because the downloads are triggered implicitly on first run.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill omits a clear privacy and data-transfer warning despite automatically contacting a third-party vendor to fetch license and model files. In agent contexts, even metadata-only outbound requests can violate user expectations or policy, and the absence of disclosure prevents informed consent about external connectivity and possible telemetry exposure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill advertises PDF-to-Word behavior but exposes a broader conversion surface, including HTML, images, JSON, Markdown, and CSV. This mismatch can violate least surprise and policy expectations, increasing the chance the skill is invoked for capabilities that were not disclosed, reviewed, or intended in this skill context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs runtime network downloads for a license file and an AI model without making that behavior part of the declared skill contract. Undeclared remote fetches create supply-chain and privacy risk because execution depends on external content that can change over time or be intercepted if the endpoint or trust chain is compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill writes persistent usage-tracking data into the user's home directory, which is unrelated to document conversion and is not disclosed in the skill description. Unexpected persistence can create privacy, compliance, and multi-tenant hygiene issues, especially in shared or ephemeral execution environments.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · License.txt (reported line 48)May include surrounding context.

text
------------------------------------------------------------------------

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.

IN NO EVENT SHALL PDF TECHNOLOGIES, INC. OR ITS AFFILIATES BE LIABLE FOR

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The parser description narrows the apparent intent to three output types, while the adjacent argument choices permit numerous other formats such as HTML, RTF, image, TXT, JSON, Markdown, and CSV. This is an active documentation-to-code inconsistency, not just omitted detail.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/pdf-to-word-docx.py (reported line 294)May include surrounding context.

python
def resolve_converter(format_name: str):
    method_name = get_converter_method_name(format_name)
    converter = getattr(CPDFConversion, method_name, None)
    if converter is None:
        raise RuntimeError(f"Current SDK does not provide converter method: {method_name}")
    return converter

Static analysis

No suspicious patterns detected.