Back to skill

Security audit

pdf

Security checks for vulnerabilities and agentic risk

Overview

This PDF skill is a coherent local PDF-processing guide with helper scripts, though users should handle generated PDF, image, and JSON outputs carefully because they may contain sensitive document data.

Install only if you want an agent to process local PDFs. Run examples on copies when modifying or repairing files, use decryption only for documents you are authorized to access, and store or delete generated JSON, images, text, and filled PDFs according to the sensitivity of the original document.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a general-purpose PDF manipulation toolkit with many capabilities. The supplied code chunk, however, is only a test file for get_bounding_box_messages, checking intersections and sizing constraints for form-field bounding boxes. That is at most a narrow support component related to PDF form layout validation, not evidence of text/table extraction, PDF creation, merging, splitting, or comprehensive form handling. Because the actual code's primary purpose is materially narrower and different from the declared toolkit description, this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The code’s primary behavior is rasterizing a PDF into per-page PNG images. The declared description focuses on PDF manipulation such as text/table extraction, PDF creation, merging/splitting, and form handling. While the broader phrase about programmatically processing or analyzing PDF documents is somewhat adjacent, PDF-to-image conversion is a distinct capability not explicitly covered by the listed functions. Because this code exports images rather than performing the described PDF-centric operations, there is a meaningful description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The qpdf --decrypt example demonstrates removal of PDF password protection and writes an unprotected output without any warning about sensitivity, authorization, or secure handling. In a general-purpose agent skill, this can normalize bypassing document protections and lead users or automated workflows to create plaintext copies of confidential files that are easier to exfiltrate, mishandle, or retain insecurely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow explicitly instructs creation of field_values.json and a filled output PDF containing user-supplied form data, but provides no warning that these files may persist sensitive personal information on disk. In a PDF-form-filling skill, this creates a realistic risk of local data exposure through leftover artifacts, backups, shared workspaces, or later reuse of those files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The non-fillable workflow directs the user to generate fields.json, validation images, and a filled PDF, all of which can contain or reveal personal or sensitive form contents, page layouts, and entered values. Because the skill requires repeated image generation and manual validation, it increases the number of persistent artifacts and therefore the chance that sensitive information is exposed or retained unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown reference includes numerous commands and code examples that write new files, extract embedded content, or directly modify existing PDFs, including qpdf --replace-input corrupted.pdf. Under the markdown-file criteria, the document should warn users about behaviors that can affect user data or system integrity, but no such caution appears near these examples or elsewhere in the document.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code extracts form field metadata from a PDF and saves it as JSON, which is a file write involving potentially sensitive document structure or contents. While it prints a completion message after writing, there is no prior warning or disclosure in this file that running the script will create an output file containing data derived from the input document.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.