Back to skill

Security audit

MinerU PDF Parser

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward MinerU API usage guide; it sends documents to MinerU for parsing and needs better privacy and token-handling guidance, but the behavior matches its stated purpose.

Install only if you are comfortable using MinerU as an external document-processing service. Do not submit confidential, regulated, or proprietary documents unless your policy allows it, and store MINERU_TOKEN in a protected secret manager or restricted credential file rather than committing it or placing it in shared profiles.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:157
Finding

Persistent Plaintext Storage of an API Token

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:157
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: Medium

bash
export MINERU_TOKEN="your_api_key_here"

Technical Analysis

The Skill documentation recommends assigning the MinerU API token through a persistent shell configuration file or the OpenClaw configuration. Although using an environment variable avoids embedding the token directly into API commands, placing its plaintext value in a shell startup file or inadequately protected application configuration leaves the credential readable at rest.

Any process or account capable of reading the relevant configuration file could recover the token. It may also be exposed through workstation backups, diagnostic bundles, accidental repository commits, configuration synchronization, or disclosure of the user's home directory.

Attack Path

  1. A user follows the documented guidance and stores a valid MinerU token in a persistent configuration file.
  2. An attacker, malicious local process, compromised backup service, or unintended repository recipient obtains read access to that file.
  3. The attacker extracts the value assigned to MINERU_TOKEN.
  4. The attacker supplies the stolen token in the Authorization: Bearer header when calling the MinerU API.
  5. The API accepts requests under the victim's account until the credential is revoked or expires.

Impact Assessment

Exploitation requires access to the configuration file or a copy of it; the documented instruction does not independently grant such access. A recovered token could permit unauthorized MinerU API requests within the permissions and service limits associated with the token, potentially causing quota consumption, financial cost, unauthorized task submission, and access to API resources available to that credential. This issue does not provide operating-system privilege escalation by itself.

Remediation
View remediation

Remediation Suggestions

  • Prefer an operating-system keychain, OpenClaw secret store, or dedicated secrets manager instead of storing the token directly in a shell startup file.
  • If file-based storage is unavoidable, use a dedicated credential file outside the project directory and restrict it to the owning user, such as with permissions equivalent to 0600.
  • Add explicit guidance never to commit credentials to source control, synchronize them through untrusted services, include them in support bundles, or place them in shared shell profiles.
  • Keep only a placeholder in documentation and configuration templates.
  • Use narrowly scoped and short-lived credentials where the MinerU service supports them.
  • Rotate the token immediately if its configuration file is accidentally disclosed, committed, or copied to an untrusted location.
  • Configure secret scanning and repository ignore rules to detect or prevent accidental token commits.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill repeatedly instructs users to submit document URLs, upload files via presigned URLs, and send them to the MinerU API, but it does not clearly warn that document contents and metadata are transmitted to an external third-party service. This is a real privacy and data-governance issue because users may process sensitive documents under the false assumption the parsing is local or first-party.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This example demonstrates sending a document URL and authentication token to an external API endpoint for processing. In the context of a document parsing skill, that external transmission is expected functionality, but it is still security-relevant because sensitive document contents may be disclosed to a third party without sufficiently explicit warning or handling guidance.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

bash
# 1. 提交任务
curl -X POST "https://mineru.net/api/v4/extract/task" \
  -H "Authorization: Bearer $MINERU_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The integrated workflow again submits a document URL to the MinerU service and uses a bearer token, creating the same third-party data exposure concern in a more automation-oriented context. Because it is framed as an OpenClaw workflow, users may be more likely to operationalize it at scale, increasing the risk of unintentionally transmitting sensitive research or internal documents externally.

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

md
cd "./paper-reading/[CVPR 2025] NewPaper"

# 2. 提交解析任务
TASK_ID=$(curl -s -X POST "https://mineru.net/api/v4/extract/task" \
  -H "Authorization: Bearer $MINERU_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"url": "https://arxiv.org/pdf/XXXX.XXXXX"}' | jq -r '.task_id')

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill supports multiple language options, but this usage guidance directs users toward a specific locale choice for a class of documents. Although not a strong violation, it may be read as prescriptive locale guidance rather than user-driven selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.