Back to skill

Security audit

PDF Split

Security checks for vulnerabilities and agentic risk

Overview

This skill locally splits user-selected PDF files and does not show hidden, networked, persistent, or destructive behavior.

Install only if you are comfortable with a Node-based PDF utility and consider pinning pdf-lib or using a lockfile before deployment. Run it on PDFs you intend to process, choose output paths deliberately, and treat the Chinese-only help text as a usability limitation rather than a hidden security behavior.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned Third-Party PDF Processing Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 9-11
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

yaml
install:
  - kind: npm
    package: pdf-lib

Technical Analysis

The installation metadata requests pdf-lib without specifying an exact version. The project also contains no dependency lockfile or integrity hash that would bind installation to a reviewed package artifact.

Consequently, separate installations may resolve to different package versions. The effective dependency code can change after this skill has been reviewed, exposing the installation and PDF-processing workflow to upstream package compromise, malicious publication, or an unexpectedly incompatible release.

This finding does not establish that the current pdf-lib package is malicious. It identifies a supply-chain weakness caused by mutable dependency resolution.

Attack Path

  1. An attacker compromises the upstream package publisher, package registry account, or dependency distribution channel.
  2. The attacker publishes a malicious version that satisfies the unversioned dependency request.
  3. A user or skill manager installs the skill and resolves the newly published package.
  4. Malicious dependency code executes through an installation lifecycle script, module loading, or PDF-processing operation.
  5. The payload operates with the privileges of the account running the installation or skill.

Impact Assessment

Successful exploitation could allow arbitrary code execution with the privileges of the user running the skill. Depending on that user's permissions, an attacker could access local PDFs and other readable files, modify writable files, use available credentials, or initiate network communication. The impact is limited by the operating-system privileges and sandbox restrictions applied to the skill process.

Remediation
View remediation

Remediation Suggestions

  • Pin pdf-lib to an exact, reviewed version rather than allowing mutable resolution.
  • Add and retain a package lockfile containing registry-resolved integrity hashes.
  • Install dependencies using a deterministic command such as npm ci.
  • Restrict dependency retrieval to the official trusted registry and reject unexpected registry overrides.
  • Review dependency provenance, release history, lifecycle scripts, and known vulnerabilities before updating.
  • Perform upgrades through an explicit review process and regenerate the lockfile only after validating the new artifact.
  • Run the skill with least privilege and isolate PDF processing from sensitive files, credentials, and unnecessary network access.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file description and later CLI messages are written in Chinese, which imposes a specific language on users by default. Under the policy, forcing a language or locale without opt-in is a natural-language policy violation unless the tool is explicitly documented as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description and main usage text are presented exclusively in Chinese, which can impose a language constraint on users without opt-in. The policy allows justified locale constraints or explicit language choice, neither of which is documented here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.