Back to skill

Security audit

银行承兑汇票切割

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward PDF-splitting helper, with ordinary file-output and dependency-installation cautions but no evidence of hidden or malicious behavior.

Install dependencies only from trusted package sources, ideally inside a virtual environment. Run the script only on PDFs and directories you choose, use a private output folder for sensitive documents, and be aware that existing output files with the same names may be overwritten.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:211
Finding

Unpinned Python Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 211 and 214
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Complete Vulnerable Code Snippet:

bash
pip install pypdf
bash
pip install pdf2image pytesseract

Technical Analysis

The installation instructions retrieve the latest available versions of three Python packages from the package index configured in the user's environment. No versions, integrity hashes, lock file, or verified package source are specified.

Python package installation may execute package-controlled build or installation logic. Consequently, the effective code installed by these commands can change after the Skill has been reviewed. A compromised package release, compromised package repository, dependency-confusion condition, or malicious package-index configuration could result in attacker-controlled code being installed and executed.

The package names do not exhibit an evident typographical-squatting pattern, and the audited Skill does not itself retrieve a known malicious package. The risk arises from mutable, unverified dependency resolution.

Attack Path

  1. An attacker compromises a referenced package, its publishing account, the configured package index, or the user's package-resolution environment.
  2. The attacker publishes or serves a malicious package version under a dependency name resolved by pip.
  3. A user follows the Skill instructions and runs the unpinned installation command.
  4. pip downloads the attacker-controlled version because no approved version or integrity hash is enforced.
  5. Malicious installation logic or imported runtime code executes with the privileges of the user running pip.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the installing user. This may permit access to that user's files, environment variables, credentials available to the pr ...[truncated 234 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to a reviewed version.

  2. Place dependencies in a version-controlled requirements or lock file.

  3. Record cryptographic hashes and enforce them during installation, for example:

    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Review and pin transitive dependencies as well as direct dependencies.

  5. Recommend installation inside a dedicated virtual environment with no administrative privileges.

  6. Use a trusted package index or an internally controlled package mirror.

  7. Add a documented dependency-update process that includes security review and hash regeneration.

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:116
Finding

Predictable Output Files Are Overwritten Without Safety Checks

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 116; equivalent write patterns also appear at lines 292 and 333
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Low

Complete Vulnerable Code Snippet:

python
with open(output_path, 'wb') as output_file:
    writer.write(output_file)

Technical Analysis

The generated output path uses a predictable filename and is opened in wb mode. This mode follows symbolic links and truncates an existing target before writing. The implementation does not check whether the destination already exists, whether it is a symbolic link, or whether the selected output directory is controlled by another user.

The same unsafe write pattern is repeated in the page-range and grouped-splitting examples. In normal private directories, the most likely consequence is accidental replacement of an existing PDF. In a shared or attacker-writable directory, an attacker could pre-create a symbolic link at the expected output path and redirect the write to another file writable by the victim.

Exploitation is constrained by operating-system permissions: this behavior does not allow the process to modify a target that the invoking user cannot already write.

Attack Path

  1. The victim processes a PDF in a shared or attacker-writable output directory.
  2. The attacker predicts the generated filename, such as document_p1.pdf.
  3. The attacker creates that path as a symbolic link to another file writable by the victim, or places an existing file at that location.
  4. The victim invokes the PDF-splitting code.
  5. open(output_path, 'wb') follows the symbolic link or opens the existing file and truncates it.
  6. The PDF writer replaces the target's contents with generated PDF data.

Impact Assessment

The vulnerability can cause loss or corruption of files writable by the invoking user. In a symbolic-link attack, the affected file may be outside th ...[truncated 226 chars]

Remediation
View remediation

Remediation Suggestions

  1. Refuse to replace existing files by default by using exclusive creation:

    python
    with open(output_path, 'xb') as output_file:
        writer.write(output_file)
    
  2. Provide an explicit overwrite option rather than silently truncating existing files.

  3. Check that the output directory is trusted and not writable by untrusted users.

  4. Reject symbolic-link destinations and validate the resolved destination remains within the intended output directory.

  5. For stronger race-condition resistance, use platform-appropriate no-follow and exclusive-creation flags.

  6. Write to a securely created temporary file in the destination directory, flush and synchronize it, and atomically rename it only after successful generation.

  7. Apply the same protections to the write operations at lines 292 and 333.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
brew install tesseract tesseract-lang

# Ubuntu/Debian:
# sudo apt-get install tesseract-ocr tesseract-ocr-chi-sim

# Windows:
# 下载安装包: https://github.com/UB-Mannheim/tesseract/wiki

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Manifest和前文功能说明将技能限定为“只提取包含显示日期的页面”。但“进阶用法”中的代码示例实现了不依赖该日期标识的通用PDF拆分能力,包括任意页范围提取和按页数组分组切割,明显超出已声明的技能范围。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

split_pdf_by_pages 的函数签名和docstring说明可通过 keyword 参数搜索指定关键词,默认才是“显示日期”。但实际判断和日志输出在 L082、L096、L101、L104 处均直接硬编码为“显示日期”,完全忽略 keyword 参数,导致代码行为与文档声明相矛盾。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file describes creating separate PDF files from pages matching a keyword, which duplicates potentially sensitive document content onto disk. While it mentions overwrite behavior, it does not warn users that extracted pages may contain private information and will be saved as additional files in the output location.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.