Back to skill

Security audit

epub-to-pdf-skill

Security checks for vulnerabilities and agentic risk

Overview

This EPUB-to-PDF skill has a clear purpose, but a crafted EPUB could make the converter access local or internal resources, and the install guidance uses broad system-level dependencies.

Review before installing or using on untrusted EPUBs. Run it in an isolated container or low-privilege environment without sensitive local files or internal network access, avoid system-wide pip installation, and prefer a version that restricts WeasyPrint resource fetching and uses per-run temporary files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/epub2pdf.py:55
Finding

Untrusted EPUB Resources Can Trigger Server-Side and Local Resource Access

Content
View full analysis
``` or: ```html ``` 2. A user or automa ...[truncated 1017 chars]
Remediation
View remediation
, url_fetcher=)` rather than relying on unrestricted default fetching. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/epub2pdf.py:107
Finding

Predictable Shared Temporary File Enables Symlink, Collision, and Disclosure Risks

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned System-Wide Dependency Installation Creates Supply-Chain and Integrity Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The description and overview state that the skill is specifically for CJK text support, which is a locale/language-specific constraint. The file does not explicitly present this as an optional mode or clearly justify it as a region-specific tool, so it may conflict with language/locale neutrality expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The generated document sets <html lang="zh-CN"> unconditionally, which imposes a specific language/locale setting regardless of the input EPUB or user preference. This matches the policy category for forced locale behavior because the file does not offer opt-in, selection, or justification for always using Chinese locale metadata.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.