Back to skill

Security audit

PDF to Markdown

Security checks for vulnerabilities and agentic risk

Overview

This skill locally converts PDFs to Markdown and its file access is aligned with that purpose, with the main caution being an unpinned third-party Python dependency.

Install in a normal least-privileged environment and consider pinning or reviewing the pdfplumber version before use, especially for sensitive PDFs. The skill should only need access to the input PDF and the intended output location.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:27-30 (also declared at SKILL.md:57 and imported at pdf2md.py:12-16)
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

The installation instructions and package metadata specify pdfplumber without a fixed version or integrity hash:

markdown
## Requirements

```bash
pip install pdfplumber
text

The dependency is also declared without a version constraint:

```yaml
    pypi: ["pdfplumber"]

The application imports the package at runtime:

python
try:
    import pdfplumber
except ImportError:
    return "Error: pdfplumber not installed"

Technical Analysis

Installing an unpinned dependency causes the resolved package code to vary over time. Consequently, the package executed by users may differ from the version that was reviewed during this audit. No evidence indicates that the current pdfplumber package is malicious; the risk arises from the absence of version and integrity controls.

If a future release, package repository account, distribution channel, or transitive dependency is compromised, installation may introduce attacker-controlled code. Python packages can execute installation-related logic, and imported package code runs with the privileges of the user invoking the converter. The dependency also directly processes potentially sensitive PDF documents.

Attack Path

  1. An attacker compromises the dependency's release process, repository account, package distribution channel, or a transitive dependency.
  2. The attacker publishes a malicious or backdoored version that satisfies the unrestricted package name pdfplumber.
  3. A user follows the documented pip install pdfplumber command, or the Skill environment resolves the unversioned metadata declaration.
  4. The package manager installs the attacker-controlled release.
  5. Malicious code executes during installation or when `pdfp ...[truncated 682 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin pdfplumber to a specifically reviewed version in both the installation instructions and Skill metadata.
  2. Maintain a lock file that pins all transitive dependencies.
  3. Record and verify package hashes, such as through a hashed requirements file and pip install --require-hashes.
  4. Install packages exclusively from the official, trusted package index over authenticated TLS.
  5. Review dependency updates before changing pinned versions and use automated supply-chain vulnerability scanning.
  6. Run PDF conversion under a dedicated, least-privileged account or sandbox with access limited to the required input and output files.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.