Back to skill

Security audit

PDF to Structured Markdown Skill(ADP)

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent document-conversion purpose, but its installation and bundled command guidance expose users to high-impact code-execution and broader ADP account actions than the main skill description suggests.

Install only if you are comfortable with the ADP cloud service processing your documents and with installing Laiye's CLI. Prefer a pinned package version or a reviewed release binary; avoid the curl|bash and irm|iex installer commands unless you have independently inspected and verified the scripts. Do not let an agent run extraction or custom-app create/update/delete commands unless you explicitly asked for those ADP account changes.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:80
Finding

Unpinned Remote Installer Scripts Are Downloaded and Executed Directly

Content
View full analysis
Remediation
View remediation
adp-init.sh" | sha256sum --check - less adp-init.sh bash adp-init.sh ``` 6. On Windows, use an Authenticode-signed script or binary and verify the signature before execution. 7. Prefer a fixed, audited package or signed release binary instead of a mutable branch installer. 8. Advise users not to run the installer with administrator or root privileges unless a documented operation specifically requires them. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:75
Finding

Unpinned npm Package Is Installed Globally

Content
View full analysis
Remediation
View remediation
``` 2. Prefer project-local installation over global installation where operationally feasible. 3. Commit and enforce a lockfile for project-local installations. 4. Verify npm integrity metadata and package provenance in the release process. 5. Publish signed releases and document how users can verify the publisher and artifact. 6. Disable lifecycle scripts with `--ignore-scripts` when the package does not require them. 7. Review the package contents and lifecycle scripts before approving a new version. 8. Use an explicit update procedure rather than silently resolving every installation to the latest release. 9. Run installation with a non-administrative account and limit filesystem permissions to the minimum required. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Piping the downloaded content directly into bash removes any opportunity for inspection or integrity validation before execution. In the context of an agent skill, this is especially risky because automation can normalize unsafe command chaining and turn documentation into a one-step arbitrary code execution path.

Content

Scanner excerpt · README-CN.md (reported line 29)May include surrounding context.

bash
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The curl ... | bash pattern is a classic command-chaining anti-pattern that executes remote content immediately without giving the user or agent a chance to inspect it. In an AI skill ecosystem, this is more dangerous because an automated agent may reproduce the exact installation command non-interactively, turning any upstream compromise into immediate arbitrary code execution.

Content

Scanner excerpt · README.md (reported line 30)May include surrounding context.

bash
# Method 2: Shell script (Linux / macOS, when npm is not available)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The use of a pipe into bash is a classic chaining pattern that collapses download and execution into a single step, eliminating the opportunity for inspection and increasing the blast radius of upstream compromise. In a skill meant for document conversion, this system-level execution path is disproportionate to the stated purpose and makes successful compromise more dangerous.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

bash
# Method 2: Shell script (Linux / macOS, when npm is not available)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes a much broader ADP platform with parsing, extraction, task management, and application management features, while the skill metadata presents a narrower PDF-to-structured-Markdown capability. This scope mismatch can mislead an agent or user into invoking capabilities beyond the declared trust boundary, increasing the chance of unintended data processing or remote actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation promises standard JSON extraction output instead of the manifest’s stated Markdown conversion behavior. This inconsistency is security-relevant because downstream agents may treat the skill as a passive formatter while it actually performs richer document extraction and structured output generation, potentially exposing more sensitive content than expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README instructs users to execute remotely fetched shell and PowerShell installer scripts without any integrity verification, pinning, or security warning. This is dangerous because compromise of the remote source, repository, or network path could lead to arbitrary code execution on the host running the skill setup.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises custom application creation, update, and deletion commands that exceed a simple document-to-Markdown skill. These administrative capabilities can alter remote service state and broaden the attack surface substantially, especially if an agent is allowed to execute documented commands automatically.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Custom application management is not justified by the stated purpose of converting documents to Markdown. In skill context, this makes the capability more dangerous because a consumer expects content transformation, not remote creation or deletion of extraction applications, leading to privilege creep and possible destructive actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises capabilities well beyond the skill's declared PDF-to-Markdown scope, including key-field extraction, app management, and broader agentic automation. In an agent setting, this kind of scope expansion can cause the model or operator to invoke unintended high-privilege or data-processing functions, increasing the chance of over-collection, unauthorized actions, or use outside the user's expected consent boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README shows local-file and URL processing commands but does not explicitly warn that supplied documents and URLs are sent to a remote ADP cloud service. For a document-processing skill, this omission is significant because users may provide sensitive PDFs, scans, contracts, or invoices under the assumption of local-only handling, leading to unintentional data disclosure to a third party.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The command list exposes extraction and custom-app lifecycle operations that exceed a simple document-to-Markdown conversion skill. In a tool-using agent context, authoritative command documentation can directly shape agent behavior, so these extra operations materially increase the attack surface and risk of unintended remote actions, configuration changes, or sensitive-field extraction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to parse local files, URLs, and Base64-encoded documents via a remote ADP service, but it does not prominently disclose that document contents will be transmitted to a third-party platform. Users may unknowingly send sensitive contracts, IDs, invoices, or internal documents off-host, creating confidentiality, compliance, and privacy risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installation instructions include direct execution of remote shell and PowerShell content without a prominent warning about the system impact. This can mislead users into running privileged setup commands that may alter their environment or execute malicious code if the fetched content is tampered with.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill recommends installing dependencies by piping a remotely fetched shell or PowerShell script directly into an interpreter. That creates an unnecessary arbitrary-code-execution path during setup: if the upstream repository, network path, or hosting account is compromised, users may run attacker-controlled code on their systems. In the context of a document parsing skill, this installation approach is not required for core functionality and materially increases risk.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The command fetches a shell script from a remote URL at execution time. Even if hosted on GitHub, this creates trust-on-first-use risk and allows any compromise of the referenced content to become immediate local code execution during installation.

Content

Scanner excerpt · README-CN.md (reported line 29)May include surrounding context.

bash
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

External Script Fetching

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The README recommends installation by fetching and executing a remote shell script directly from GitHub. This creates a supply-chain risk because any compromise of the repository, branch, network path, or referenced script content could result in arbitrary code execution on the user's machine during installation.

Content

Scanner excerpt · README.md (reported line 30)May include surrounding context.

bash
# Method 2: Shell script (Linux / macOS, when npm is not available)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

External Script Fetching

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The documented command fetches a script from GitHub and immediately executes it with bash. External script fetching is inherently risky because trust is shifted to the remote source and transport path at runtime; compromise of the repository, maintainer account, or content can result in full local code execution.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

bash
# Method 2: Shell script (Linux / macOS, when npm is not available)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest and title present this as a PDF/document-to-Markdown parsing skill, but the documentation promotes invoice extraction, ticket extraction, ID card extraction, order extraction, and custom extraction. These capabilities are outside the stated purpose and suggest broader use of the shared CLI than this skill claims to cover.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 10)May include surrounding context.

md
1. Licensing

1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 14)May include surrounding context.

md
1. Licensing

1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 22)May include surrounding context.

md
1. Licensing

1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 32)May include surrounding context.

md
4. Disclaimer of Warranties

THE PRODUCT IS PROVIDED "AS IS", WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO: THE LICENSOR DOES NOT WARRANT THAT THE PRODUCT IS FREE FROM ERRORS, BUGS, WILL OPERATE PROPERLY, OR IS SUITABLE FOR A PARTICULAR PURPOSE; THE LICENSOR DOES NOT WARRANT THAT USE OF THE PRODUCT WILL NOT INFRINGE UPON THIRD-PARTY RIGHTS; THE LICENSOR SHALL NOT BE LIABLE TO THE LICENSEE OR ANY THIRD PARTY FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, OR PUNITIVE DAMAGES ARISING FROM THE USE OF THE PRODUCT.

5. Termination

Static analysis

No suspicious patterns detected.