Back to skill

Security audit

My Pdf

Security checks for vulnerabilities and agentic risk

Overview

This PDF skill is a straightforward document-processing guide with some sensitive-but-expected examples, and it does not install persistence, hide behavior, or ship executable payloads.

Install only if you are comfortable using PDF tools on local documents. Use it only for PDFs you own or are authorized to access, and if you need OCR dependencies, install reviewed versions in an isolated environment rather than blindly running an unpinned pip install.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:215
Finding

Unpinned Third-Party Dependencies in OCR Installation Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 215
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

python
# Requires: pip install pytesseract pdf2image

Technical Analysis

The OCR example instructs users or agents to install pytesseract and pdf2image without version constraints, package hashes, a lockfile, or an explicitly trusted package repository. Consequently, package resolution can select mutable releases that were not reviewed with the Skill.

Python package installation may execute package-controlled build or installation logic. Installed packages also execute code when imported. If a dependency or one of its transitive dependencies is compromised, replaced with a malicious release, or resolved from an attacker-controlled package index, following this instruction could result in arbitrary code execution.

No evidence establishes that the named packages are currently malicious. The vulnerability arises from the unverified and non-reproducible dependency installation process.

Attack Path

  1. An attacker compromises a dependency release, a transitive dependency, or a package source accessible to the target environment.
  2. A user or agent follows the OCR prerequisite and runs pip install pytesseract pdf2image.
  3. Because no versions, hashes, or trusted repository are enforced, pip resolves and downloads the attacker-controlled package artifact.
  4. Malicious code executes during package build or installation, or later when the package is imported by the OCR example.
  5. The code operates with the privileges of the account running pip or the subsequent Python process.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's privileges. Depending on that account's access, an attacker could read or modify local files, access PDF contents and process-visible secrets, alter generated output ...[truncated 215 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin each direct dependency to a reviewed, exact version.

  • Generate and retain a lockfile that also constrains transitive dependencies.

  • Require cryptographic hashes, such as with pip install --require-hashes -r requirements.txt.

  • Configure installation to use an explicitly trusted package index and disable unapproved extra indexes.

  • Install dependencies inside an isolated virtual environment or container under a least-privileged account.

  • Scan and periodically review dependency versions and transitive dependency changes.

  • Replace the inline installation instruction with a reviewed requirements file, for example:

    text
    pytesseract==<reviewed-version> --hash=sha256:<verified-hash>
    pdf2image==<reviewed-version> --hash=sha256:<verified-hash>
    
  • Document required system-level OCR components separately and verify their packages through the operating system's trusted package repository.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation text is very broad: it suggests invoking the skill whenever the assistant needs to process, generate, analyze, or fill PDFs "at scale." Overly broad routing increases the chance the agent will use this skill in sensitive contexts without tighter user-intent checks, potentially exposing confidential PDF contents or triggering powerful document operations unnecessarily.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The qpdf example includes decryption/password removal instructions without any warning about authorization, legality, or handling of protected documents. In an agent setting, this can normalize or enable bypass-style workflows on encrypted PDFs, especially if the assistant applies the example to documents the user is not permitted to decrypt.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.