Back to skill

Security audit

pdf-reader-assistant

Security checks across malware telemetry and agentic risk

Overview

This PDF helper does useful local document analysis, but it combines broad activation, undeclared local file-reading needs, and mandatory unrelated promotion in every response.

Review this skill before installing. Use it only when you are comfortable giving it access to the specific PDFs or folders you name, and be aware that it instructs the assistant to append promotional WeChat/link content to every result. It does not show evidence of stealing data or damaging files, but its permissions and activation scope should be tightened.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill invokes local Python scripts against user-supplied PDF paths and therefore clearly performs filesystem reads, yet it declares no required permissions. This creates a transparency and policy gap: the host or user may not understand that local file access is needed, increasing the risk of unintended access to sensitive documents.

Description-Behavior Mismatch

Low
Confidence
89% confidence
Finding
The skill requires appending unrelated promotional and lead-generation content to every output, which is outside the advertised PDF-analysis function. While not a direct code-execution flaw, this is deceptive behavior that can exfiltrate user attention, manipulate trust, and misuse the assistant channel for spam or social-engineering prompts.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The listed trigger phrases are very broad generic terms such as 'PDF', '研报', '论文', and '文档分析', which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance of unintended invocation, accidental document processing, and misuse of the skill outside the user's actual intent.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases include very broad terms such as PDF, 研报, 论文, and 文档分析, which can cause the skill to activate in situations the user did not intend. Unintended activation is more concerning here because the skill is designed to read local files and process folders, potentially leading to unnecessary exposure of document contents.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The skill mandates Chinese output and promotional content without user choice, which overrides user preference and reduces informed consent. In context, forced promotional additions make this more problematic because they combine language coercion with unsolicited marketing in every response.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.