Back to skill

Security audit

pdf

Security checks for vulnerabilities and agentic risk

Overview

This is a local PDF-processing guide whose file writes and password/PDF operations fit its stated purpose, with some safety warnings users should add or follow.

Install/use is reasonable for local PDF work, but process only documents you are authorized to handle, choose output paths carefully, keep backups before in-place repair commands, avoid putting real passwords directly on command lines, and delete temporary form JSON/images when they contain sensitive data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:215
Finding

Unpinned Third-Party Dependencies Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
pdf2image== ``` 2. Maintain dependencies in a lockfile generated from a reviewed environment. 3. Require package hashes, for example through a hash-locked requirements file and: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Explicitly use a trusted package index and prevent unintended fallback to untrusted extra indexes. 5. Review and pin transitive dependencies as well as direct dependencies. 6. Recommend installation inside an isolated virtual environment or restricted container. 7. Warn users not to install dependencies with administrator or root privileges. 8. Add automated dependency vulnerability and provenance checks to the release process. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown skill guide includes examples that create or overwrite output files such as merged.pdf, split pages, rotated.pdf, encrypted.pdf, and decrypted.pdf, and it also shows password removal with qpdf. The document does not include any warning that these operations modify user files, create derived copies, or may expose protected document contents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains operational examples for adding and removing PDF password protection, including a literal password on the command line. Under the markdown-file criteria for missing warnings, the document omits any caution about exposing secrets in shell history or about modifying access controls on protected documents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The troubleshooting section recommends an in-place file modification command that can overwrite the source PDF, but provides no user-facing warning about the risk to original data. For markdown files, behaviors affecting user data or system integrity should be disclosed clearly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs the user to generate a filled PDF containing form data, but it provides no warning that the output file will persist potentially sensitive personal information on disk. In a PDF-form workflow, users may handle PII, financial, medical, or legal data, so omission of data-handling guidance increases the risk of unintended local retention or later disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The non-fillable workflow requires creating fields.json, validation images, and a filled PDF, all of which can embed or reveal sensitive user-supplied form contents and document structure, yet the skill gives no warning about persistence of these artifacts. This is especially relevant because validation images and JSON files may duplicate sensitive information and broaden the exposure surface beyond the final PDF alone.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.