Back to skill

Security audit

Double6 PDF Translation

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches its PDF-translation purpose, but it has review-worthy risks around API-key exposure, insecure endpoint handling, and unpinned executable dependencies.

Install only if you are comfortable sending PDF contents to the selected model provider. Use a trusted HTTPS endpoint, prefer a dedicated virtual environment, avoid highly sensitive documents until API-key handling is fixed, and review or pin the pdf2zh_next dependency before production use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/preflight_runtime.py:303
Finding

API Credentials and Document Content Can Be Transmitted over Plaintext HTTP

Content
View full analysis
dict[str, Any]: config_check = check_endpoint_config(args) if config_check["status"] == "fail": return config_check base_url = str(args.base_url or "").rstrip("/") parsed = urlparse(base_url) if "api.deepseek.com" in parsed.netloc or base_url.endswith("/chat/completions"): return _chat_endpoint_probe(args, base_url) request = Request( base_url + "/models", headers={"Authorization": f"Bearer {args.api_key}", "Accept": "application/json"}, method="GET", ) try: with urlopen(request, timeout=float(args.endpoint_timeout)) as response: ``` The direct translator sends both the credential and document text using the accepted URL: ```python payload: dict[str, Any] = { "model": args.model, "messages": [ {"role": "system", "content": system_prompt}, {"role": "user", "co ...[truncated 2521 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/pdf_translation_runtime.py:397
Finding

API Keys Are Exposed in Child-Process Command-Line Arguments

Content
View full analysis
str: script = Path(__file__).resolve().with_name("qwen_pdf2zh_cli_translator.py") cli_timeout = min(int(args.openai_timeout), 300) command = [ sys.executable, str(script), "--base-url", args.base_url, "--model", args.model, "--api-key", args.api_key, "--reasoning-effort", args.openai_reasoning_effort, "--temperature", str(args.temperature), "--max-tokens", str(args.cli_max_tokens), "--timeout", str(cli_timeout), "--system-prompt", args.custom_system_prompt, ] ``` The standard backend command does the same: ```python command.extend( [ "--openai", "--openai-model", args.model, "--openai-base-url", args.base_url, "--openai-api-key", args.api_key, "--openai-timeout", str(args.openai_timeout), "--openai-temperature", str(args.temperature), ``` The command is redacted for logging, but the original credential-bearing array is executed: ```python with log_path.open("w", encoding="utf-8") as log: log.write("COMMAND: " + " ".join(redacted_command(command, args.api_key)) + "\n") log.write(f"MODEL: {args.model}\n") log.write(f"BASE_URL: {args.base_url}\n") log.flush() try: proc = subprocess.run( command, cwd=output_dir, env=env, stdout=log, stderr=subprocess.ST ...[truncated 2005 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/setup_venv.sh:108
Finding

Unpinned Third-Party PDF Backend Is Installed and Executed

Content
View full analysis
/dev/null 2>&1; then echo "==> Removing wrong 'pdf2zh' dist (P1) ..." "$TMP_PYTHON" -m pip uninstall -y pdf2zh >/dev/null 2>&1 || true fi echo "==> Installing pdf2zh_next (P1) ..." "$TMP_PYTHON" -m pip install pdf2zh_next # --- P1 sanity: the installed pdf2zh CLI must carry --output --- if ! "$TMP_PDF2ZH" --help 2>&1 | grep -q -- "--output"; then ``` The same unpinned installation guidance appears in `SKILL.md`: ```bash pip install pdf2zh_next ``` ### Technical Analysis The setup script installs the latest version of `pdf2zh_next` selected by PyPI and pip dependency resolution at installation time. It does not specify a reviewed version, lock transitive dependencies, verify package hashes, or use an immutable artifact source. The installed package supplies executable backend code used by the primary workflow. That code processes user documents, communicates with model services, and receives API configuration. A future compromised, malicious, or simply incompatible upstream release would therefore execute with the file and network access granted to the Skill. The script may also reuse an existing WorkBuddy virtual environment. Installing or upgrading an unpinned package and its transitive dependencies in a shared environment can affect other applications and expands the blast radius of dependency conflicts. No evidence shows that the current `pdf2zh_next` package is malicious. The vulnerability is the absence of reproducible dependency and integrity controls. ### Attack Path 1. An ...[truncated 1261 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (100)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Undisclosed OCR execution against translated page images adds extra file processing and potentially subprocess execution beyond the stated workflow. While not inherently malicious, hidden OCR/audit stages may expose more document content to local tools and broaden the dependency and command-execution surface.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code can automatically inspect the input PDF for arXiv IDs and then download LaTeX source from arxiv.org, which broadens data ingress beyond the user-supplied PDF and explicitly selected local LaTeX described in the skill metadata. This creates an unexpected network-fetch and remote-content execution path, after which untrusted downloaded source may be compiled or otherwise processed locally, increasing exposure to malicious TeX content, decompression bombs, or supply-chain abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file includes natural-language product behavior that is locale-specific: translating English PDFs into Simplified Chinese. Under the policy, forcing a specific language without user opt-in can be a language/locale policy violation, and the changelog does not mention that users can choose another output language.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises significant capabilities in prose, including file reads/writes, network access, shell execution, and environment handling, but does not declare machine-readable tool scope such as permissions or allowed-tools. This weakens sandboxing and review controls because a host may grant broader access than necessary or be unable to enforce least privilege consistently.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.