Back to skill

Security audit

cn-pdf-assistant

Security checks for vulnerabilities and agentic risk

Overview

This is a local Chinese PDF utility with disclosed file reading and output generation, with minor documentation mismatches but no hidden network, credential, persistence, or destructive behavior found.

Install only if you are comfortable with a Chinese-language local PDF tool that writes output files to disk. For sensitive documents, review or override the default OCR output path and remove plaintext OCR results when no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill description is mostly aligned with the code's primary purpose: local PDF handling with text extraction, summary, Q&A, splitting, and OCR. The code appears to operate locally and does not show remote transmission, which is consistent with the privacy claim. However, there are material discrepancies. First, the description promises table export, but the code only extracts table structures and prints counts; it does not export them to CSV/Excel/JSON files. Second, the claimed 'intelligent summary' is implemented as a lightweight heuristic rather than a more substantive summarization system, though this alone is a softer mismatch. Third, the module docstring mentions translation support, but no translation action exists in the code. Overall, the description overstates at least one user-facing capability (table export), so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language descriptions exclusively in Chinese in the module docstring, and later user-facing CLI help/messages are also Chinese. Under the policy rule, forcing a specific language without offering an alternative or opt-in is a locale/language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The argument parser description and help text are user-facing natural language, but they are only provided in Chinese. Because the script does not offer a language/locale choice, it enforces a single language for interaction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The OCR path persists extracted document text to disk by default, which can unexpectedly store sensitive contents from private PDFs in a predictable location. In a tool advertised as local/privacy-preserving, silent persistence increases confidentiality risk because users may assume processing is ephemeral and may leave recoverable plaintext on disk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The manifest repeatedly frames the skill as a local PDF-processing utility with no network involvement, but the bundled skill file includes an external homepage URL and a web diagnostic link. While this is documentation rather than executable code, it introduces network-oriented behavior expectations that do not align with the strictly local-only description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest describes text extraction, summarization, table export, keyword Q&A, PDF splitting, and OCR, all as local PDF-processing functions. However, the module docstring explicitly claims support for '翻译' (translation), which is outside the stated manifest scope and is not reflected elsewhere in the advertised capabilities.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The top-level documentation says the script supports '翻译', alongside summary, Q&A, table extraction, and page operations. No function, CLI action, or implementation in the file performs translation, so the documentation actively misstates the code's behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.