Back to skill

Security audit

mineru document extractor

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent document-extraction skill that discloses remote MinerU processing, with install and credential-handling cautions users should understand.

Install only if you are comfortable sending document or webpage content to MinerU for processing. Use a pinned or reviewed CLI version where possible, avoid sensitive private documents or internal URLs unless approved, and manage MinerU tokens carefully if you enable authenticated modes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:23
Finding

Unpinned Executable Dependencies Allow Supply-Chain Payload Substitution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15 and 23–29
Vulnerability Type: Unpinned third-party executable dependencies
Risk Level: Medium

The Skill metadata and installation instructions obtain the mineru-open-api executable without pinning it to an immutable, audited version.

json
"install":[
  {
    "id":"npm",
    "kind":"node",
    "package":"mineru-open-api",
    "bins":["mineru-open-api"],
    "label":"Install via npm"
  },
  {
    "id":"go",
    "kind":"go",
    "bins":["mineru-open-api"],
    "label":"Install via go install",
    "os":["darwin","linux"]
  }
]
bash
npm install -g mineru-open-api
bash
go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latest

Technical Analysis

Both documented installation mechanisms resolve mutable upstream artifacts at installation time. The npm command installs whichever package release currently satisfies the implicit latest-version selection, and the Go command explicitly requests @latest. Neither mechanism pins an audited version, immutable source commit, checksum, or cryptographic signature.

Consequently, the code executed by users can differ from the code that existed when this Skill was reviewed. An upstream package compromise, maintainer-account takeover, malicious release, or repository compromise could replace the expected CLI with attacker-controlled executable code. The global npm installation increases exposure because the resulting command is placed in the user's global executable environment.

This finding does not establish that the current upstream package is malicious. The vulnerability is the Skill's reliance on mutable executable dependencies without integrity controls.

Attack Path

  1. An attacker compromises the npm package, upstream repository, release pipeline, or a maintainer account associated with mineru-open-api.
  2. The attacker publish ...[truncated 1403 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npm dependency to a specifically reviewed version, for example:
    bash
    npm install -g mineru-open-api@<reviewed-version>
    
  2. Pin the Go installation to a reviewed semantic version or immutable commit instead of @latest:
    bash
    go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@<reviewed-version-or-commit>
    
  3. Update the Skill metadata so its installation declaration also identifies the exact approved package version.
  4. Publish expected SHA-256 checksums or use verifiable release signatures, and require integrity verification before execution.
  5. Avoid automatic upgrade guidance that resolves the latest release without review. Establish a controlled process in which new versions are audited before the pin is updated.
  6. Where practical, install the CLI in an isolated environment rather than globally, and execute it with only the filesystem and network permissions required for document extraction.
  7. Disable or carefully review package lifecycle scripts during installation when supported by the deployment process.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description includes very broad invocation examples such as generic requests to extract text from PDFs, OCR documents, convert office files, and crawl web pages. This can cause the skill to trigger for common document-related requests and automatically route user content to a remote extraction service, increasing the chance of unintended data disclosure or unexpected network access.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The skill instructs users to run mineru-open-api auth, which establishes persistent session/token state via environment variables or ~/.mineru/config.yaml. Persisting credentials on disk or in session state can expand exposure if the host is shared, if later tasks access the token unintentionally, or if the agent uses the stored credential for future remote operations without renewed consent.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
## Core MinerU workflow

1. **Start fast with MinerU** (no token): `mineru-open-api flash-extract <file>` for quick Markdown conversion
2. **Need more from MinerU?** Create token at https://mineru.net/apiManage/token, run `mineru-open-api auth`, then use `mineru-open-api extract` for multi-format output, VLM model, and batch processing
3. **Web pages with MinerU**: `mineru-open-api crawl <url>` to convert web content
4. **Check results**: output goes to stdout (default) or `-o` directory

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow and command examples allow URL inputs and web crawling, but the user-facing skill description does not prominently warn that provided URLs will be fetched and their contents transmitted to mineru.net for server-side extraction. Users may believe the tool only operates locally and unknowingly expose internal, private, or sensitive documents and pages to a third-party service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

A default OCR/language mode of ch is imposed without user opt-in, which can silently alter extraction behavior and reduce accuracy for non-Chinese documents. While not a direct exploit primitive, it can lead to incorrect parsing, mishandling of user content, and surprising behavior inconsistent with user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The agent guidance reinforces use of the Chinese default language mode instead of preserving user language choice or prompting when ambiguous. In a document-processing skill, this makes accidental mis-extraction more likely and can degrade reliability for multilingual or non-Chinese content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.