Back to skill

Security audit

pdf-to-epub-ocr

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it should be reviewed before installation because it processes untrusted PDFs with pinned risky dependencies and weak limits on resource use and leftover files.

Review before installing. Use this only on trusted or non-sensitive PDFs unless the dependencies are updated and processing is sandboxed. Set explicit file/page limits, choose a controlled output directory, and delete work directories after conversion. Do not blindly run the sudo install commands; verify the packages and sources for your system first.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/epub_generator.py:134
Finding

Unescaped document-derived chapter titles allow XHTML injection into generated EPUB files

Content
View full analysis
epub.EpubHtml: """ 创建单个章节 Args: chapter: 章节信息 css_item: CSS样式项 Returns: EPUB HTML章节对象 """ # 创建HTML内容 html_content = f""" {chapter.title}

{chapter.title}

{self._format_content(chapter.content)}
""" # 创建章节 epub_chapter = epub.EpubHtml( title=chapter.title, file_name=f'{chapter.id}.xhtml', content=html_content ) ``` ### Technical Analysis The chapter title is interpolated directly into both the XHTML `` element and the visible `<h1>` element without XML or HTML escaping. Chapter titles are derived from OCR output by `TextCleaner.detect_chapter_titles()` and can consequently be controlled through the contents of an input PDF. When no chapter title is detected, document metadata can also supply the title. The implementation correctly escapes `&`, `<`, and `>` for chapter body content in `_format_content()`, but no equivalent protection is applied to `chapter.title`. An input such as a chapter heading containing closing tags and additional XHTML can therefore alter the structure of the generated chapter document. EPUB readers differ significantly in their treatment of active content and remote resources. A permissive or vulnerable reader could process injected links, images, forms, styles, or scripts. Even w ...[truncated 1565 chars]
Remediation
View remediation
` and `

` elements. 2. Prefer constructing XHTML through an XML library such as `lxml.etree` rather than assembling it with formatted strings. XML libraries perform context-appropriate escaping automatically when text nodes are assigned correctly. 3. Treat metadata values passed to EbookLib as untrusted as well. Normalize them to strings, reject forbidden XML control characters, and enforce reasonable length limits. 4. Validate every generated XHTML document with a strict XML parser before packaging the EPUB. 5. Run an EPUB validation tool against the final artifact and fail closed if malformed markup or prohibited active content is detected. 6. Add regression tests using chapter titles containing: - `<`, `>`, `&`, single quotes, and double quotes. - Closing tags followed by injected elements. - Remote image and link elements. - Invalid XML control characters. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ocr_processor.py:53
Finding

Unbounded whole-document rasterization permits memory, CPU, and disk exhaustion

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (28)

Known Vulnerable Dependency: Pillow==10.1.0 — 16 advisory(ies): CVE-2023-50447 (Arbitrary Code Execution in Pillow); CVE-2024-28219 (Pillow buffer overflow vulnerability); CVE-2026-55379 (Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()`) +13 more

Critical
Category
Supply Chain
Confidence
94% confidence
Finding

Pillow processes untrusted image data, and this skill converts user-supplied PDFs into images before OCR, making the image parsing path directly exposed to attacker-controlled content. A vulnerable Pillow version can enable denial of service, memory corruption, or potentially code execution depending on the specific flaw and image format reached during processing.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: black==23.12.1 — 4 advisory(ies): CVE-2024-21503 (Black vulnerable to Regular Expression Denial of Service (ReDoS)); CVE-2024-21503 (Versions of the package black before 24.3.0 are vulnerable to Regular Expression); CVE-2026-31900 (Black is the uncompromising Python code formatter. Black provides a GitHub actio) +1 more

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 50)May include surrounding context.

text
*.log

# API Keys and secrets
.env
*.key
*.pem

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明的核心能力是“扫描版PDF经OCR后转换为结构化EPUB”,这是一个以PDF输入和OCR处理为中心的转换流程。但代码片段的实际职责只是EPUB生成器:接收已存在的结构化章节数据,生成HTML章节、目录、CSS、封面与元数据,并输出.epub文件,还提供简单校验。代码中没有任何与PDF相关的输入处理、OCR引擎调用、文本/版面识别、章节切分自PDF获取等逻辑。因此其主要目的与声明存在实质性不一致。虽然EPUB生成可能是整个系统中的下游组件,但就该代码片段本身而言,它并不能代表所声明的“PDF转EPUB(含OCR)”能力。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明的核心能力是把扫描版PDF转换成“结构化精排的EPUB格式”电子书,这意味着除OCR外,还应包含版面/章节结构化处理以及EPUB文件生成。实际代码只覆盖了其中的前置子步骤:PDF转图片、OCR识别、并行处理、置信度统计和文本汇总。代码没有看到任何EPUB打包、目录生成、HTML/XHTML生成、元数据处理、结构化排版或电子书输出逻辑。因此其实际行为明显窄于且不同于声明的主要目的,属于描述与行为不一致。

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: PyPDF2==3.0.1 — 2 advisory(ies): CVE-2023-36464 (pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a chara); CVE-2023-36464 (pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a chara)

High
Category
Supply Chain
Confidence
96% confidence
Finding

PyPDF2 is used to extract metadata from PDFs, and the skill explicitly accepts uploaded PDFs from users, so malformed documents can reach this parser directly. The cited infinite-loop issue can let an attacker submit a crafted PDF that hangs processing, causing denial of service and tying up worker resources.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: pytest==7.4.3 — 2 advisory(ies): CVE-2025-71176 (pytest has vulnerable tmpdir handling); CVE-2025-71176 (pytest has vulnerable tmpdir handling)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 21)May include surrounding context.

  1. Tesseract OCR引擎
    bash
    # Ubuntu/Debian
    sudo apt-get install tesseract-ocr tesseract-ocr-chi-sim
    
    # macOS
    brew install tesseract tesseract-lang
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 33)May include surrounding context.

  1. Tesseract OCR引擎
    bash
    # Ubuntu/Debian
    sudo apt-get install tesseract-ocr tesseract-ocr-chi-sim
    
    # macOS
    brew install tesseract tesseract-lang
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 121)May include surrounding context.

  1. Tesseract OCR引擎
    bash
    # Ubuntu/Debian
    sudo apt-get install tesseract-ocr tesseract-ocr-chi-sim
    
    # macOS
    brew install tesseract tesseract-lang
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ocr_best_practices.md (reported line 154)May include surrounding context.

  1. Tesseract OCR引擎
    bash
    # Ubuntu/Debian
    sudo apt-get install tesseract-ocr tesseract-ocr-chi-sim
    
    # macOS
    brew install tesseract tesseract-lang
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ocr_best_practices.md (reported line 167)May include surrounding context.

  1. Tesseract OCR引擎
    bash
    # Ubuntu/Debian
    sudo apt-get install tesseract-ocr tesseract-ocr-chi-sim
    
    # macOS
    brew install tesseract tesseract-lang
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ocr_best_practices.md (reported line 171)May include surrounding context.

  1. Tesseract OCR引擎
    bash
    # Ubuntu/Debian
    sudo apt-get install tesseract-ocr tesseract-ocr-chi-sim
    
    # macOS
    brew install tesseract tesseract-lang
    

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger conditions include a broad file-upload scenario ('upload PDF and request conversion to ebook format') that can cause the skill to activate in contexts the user may not have intended. In an agent environment, ambiguous activation can lead to processing untrusted documents, unnecessary OCR work, and unexpected file creation without sufficiently explicit user confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README documents creation of EPUB files and metadata writing but does not clearly warn that the skill writes files to disk and may alter extracted title/author metadata. This can surprise users, create unintended local artifacts, and propagate inaccurate or user-unapproved metadata into generated outputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill processes uploaded PDFs, extracts metadata and text, and writes derived artifacts such as cover images and EPUB/output files, but it does not explicitly warn users that document contents will be persisted to intermediate and output files. This can create confidentiality and privacy risk, especially for sensitive documents, because users may not realize extracted text and metadata remain stored on disk beyond the immediate operation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions specify a fixed OCR language configuration of chi_sim+eng, which imposes a language/locale constraint in natural language without user opt-in. The file does not present this as an optional default or clearly justify that the skill is limited to Chinese/English documents only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document is written entirely in Chinese and presents OCR language recommendations centered on Chinese variants without offering any user language or locale choice. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · requirements.txt (reported line 21)May include surrounding context.

text
# 系统依赖说明:
# Ubuntu/Debian:
# sudo apt-get install tesseract-ocr tesseract-ocr-chi-sim poppler-utils
#
# macOS:
# brew install tesseract tesseract-lang poppler

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code unconditionally sets the book language to 'zh-CN', which is a natural-language/locale constraint applied to all generated output. The file does not offer a user opt-in or parameter to choose another language, and no region-specific justification is documented here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The constructor hard-codes the default OCR language to 'chi_sim+eng', and the surrounding docstring describes it as the standard language configuration rather than an opt-in regional setting. This is a natural-language locale policy concern because the skill biases processing toward specific languages without documenting user choice or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains natural-language documentation and later user-visible log strings entirely in Chinese, with no indication that the skill is China-specific or that users can opt into the locale. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The README is entirely written in Chinese and presents the skill as supporting '中英文混合识别', but it does not state whether users may interact in other languages or whether the Chinese-only presentation is an intentional regional limitation. Under the policy, forcing a specific language without opt-in or documented justification can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file description is written entirely in Chinese and the default body font stack is tailored to Simplified Chinese system fonts, signaling that the skill is designed around a specific language/locale. Under the policy, forcing or assuming a specific language/locale without offering user choice or documenting the constraint can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing natural-language content exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into a Chinese-only experience. Under the language/locale policy, forcing a specific language without user choice can be a policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.