Back to skill

Security audit

PDF Simple Tool

Security checks for vulnerabilities and agentic risk

Overview

This skill performs straightforward PDF splitting and PDF-to-Word conversion, with ordinary file read/write behavior and no hidden network, credential, persistence, or privilege behavior found.

Install only if you are comfortable with an npm-based local document tool. Use explicit output paths in a workspace directory, avoid overwriting important files, and consider updating or pinning dependencies before use because the supplied scan reports a vulnerable transitive nanoid version.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Known Vulnerable Dependency: nanoid==5.1.7 — 2 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-73086 (nanoid: Integer Overflow or Wraparound)

High
Category
Supply Chain
Confidence
95% confidence
Finding

The lockfile pins nanoid to version 5.1.7, which the supplied advisory metadata identifies as affected by denial-of-service style flaws involving indefinite looping on negative size inputs and integer overflow/wraparound. Even though nanoid is only a transitive dependency of docx here, vulnerable code in the dependency tree is still present and could be reachable if the library or future code paths pass attacker-influenced sizes into Nano ID generation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs the agent to create new PDF and DOCX files at output paths chosen during action mapping, but it does not clearly warn that these operations write files to disk. In an agent setting, silent file creation or overwriting can surprise users, cause data loss, or place derived documents in sensitive locations if path handling is too permissive.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The line uses Chinese-only instructional text (执行命令) inside an otherwise bilingual/English-oriented skill description, which imposes a language choice without explicit user opt-in. SQP-3 covers language or locale policy violations when a skill forces a specific language without offering a choice.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency uses a caret version range, which permits automatic installation of newer minor/patch releases instead of an exact audited version. This increases supply-chain risk because a compromised or breaking upstream release could be pulled into builds unexpectedly, though the package file alone does not indicate active exploitation.

Content

Scanner excerpt · node/package.json (reported line 6)May include surrounding context.

json
"version": "1.0.0",
  "type": "module",
  "dependencies": {
    "pdf-lib": "^1.17.1",
    "pdf-parse": "^1.1.1",
    "docx": "^9.0.0"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is not pinned to an exact version and allows semver-compatible updates to be resolved at install time. In a tool that processes PDFs, this creates avoidable supply-chain exposure because future upstream releases may introduce vulnerable or malicious code without any local source changes.

Content

Scanner excerpt · node/package.json (reported line 7)May include surrounding context.

json
"type": "module",
  "dependencies": {
    "pdf-lib": "^1.17.1",
    "pdf-parse": "^1.1.1",
    "docx": "^9.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Using a caret range for this package means installations are not fully reproducible and may resolve to different dependency code over time. That weakens software supply-chain integrity and can expose consumers to unintended vulnerable or malicious upstream versions, although the immediate risk here appears limited to dependency management hygiene.

Content

Scanner excerpt · node/package.json (reported line 8)May include surrounding context.

json
"dependencies": {
    "pdf-lib": "^1.17.1",
    "pdf-parse": "^1.1.1",
    "docx": "^9.0.0"
  }
}

Static analysis

No suspicious patterns detected.