Back to skill

Security audit

文献精读小工具

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its paper-review purpose, but its optional OCR path can follow an unvalidated remote result URL from an OCR service, which creates a real network-safety concern.

Review this skill before installing. Use it only with PDFs you are allowed to send to the configured OCR or LLM providers, keep PaddleOCR disabled unless you trust the OCR endpoint, prefer internal/self-hosted endpoints for confidential documents, and install dependencies in an isolated environment. The publisher should validate OCR result URLs and pin dependencies before this is treated as low-risk.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/extract_paddleocr.py:105
Finding

Unvalidated OCR Result URL Enables Server-Side Request Forgery

Content
View full analysis
str: headers = {'Authorization': f'bearer {api_key}'} start = time.time() while True: resp = requests.get(f'{job_url}/{job_id}', headers=headers, timeout=60) resp.raise_for_status() data = resp.json().get('data', {}) state = data.get('state') if state == 'done': return (data.get('resultUrl') or {}).get('jsonUrl', '') if state == 'failed': raise RuntimeError(f"OCR任务失败: {data.get('errorMsg', 'unknown')}") if state == 'running': prog = data.get('extractProgress', {}) ui.log(f"[OCR] job={job_id} running pages={prog.get('extractedPages','?')}/{prog.get('totalPages','?')}") if timeout_seconds > 0 and (time.time() - start) >= timeout_seconds: raise TimeoutError(f'OCR超时: {job_id}') time.sleep(max(0.2, poll_seconds)) def fetch_markdown(jsonl_url: str) -> str: resp = requests.get(jsonl_url, timeout=180) resp.raise_for_status() ``` ### Technical Analysis The OCR polling response controls `resultUrl.jsonUrl`. The application passes this value directly to `requests.get()` without validating: - The URL scheme - The destination hostname - The resolved IP address - Redirect destinations - Whether the result host belongs to the configured OCR service Consequently, a compromised, malicious, or incorrectly configured OCR endpoint can cause the application to send an HTTP request to an arbitrary destination reachable from the user's system. This includes loopback interfaces, private network ranges, link-local services, and cloud instance metadata endpoints. The f ...[truncated 1950 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/requirements.txt:1
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Future Releases

Content
View full analysis
=1.40.0 requests>=2.31.0 pdfplumber>=0.11.0 ``` ### Technical Analysis All dependencies use open-ended lower bounds. A command such as: ```bash pip install -r scripts/requirements.txt ``` may therefore install any future release satisfying those constraints. No lock file, exact version pins, or package hashes are present to ensure that the installed artifacts are the versions reviewed during the audit. The package names are conventional, and the reviewed project contains no evidence of typosquatting or a deliberately malicious dependency. The risk arises from allowing future, unreviewed package versions to enter the execution environment automatically. Python package installation and import execute package-controlled code with the privileges of the current user. A compromised upstream release, repository account, distribution channel, or transitive dependency could therefore affect the confidentiality and integrity of the environment. ### Attack Path 1. A dependency publisher, package repository account, release pipeline, or transitive dependency is compromised. 2. A malicious or otherwise unsafe future version is published under one of the accepted version ranges. 3. The user follows the documented dependency installation process. 4. The package resolver selects the new version because it satisfies the `>=` constraint. 5. Package-controlled code executes during installation or when the Skill imports the dependency. 6. The malicious package acts with the privileges and data access of the user running the installation or pipeline. This path requires a supply-chain compromise or unsafe future release; no malicious dependency is currently established by the reviewed files. ### Impact Assessment If exploite ...[truncated 565 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (24)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs the agent to read configuration files, run local scripts, install dependencies, access environment variables for API keys, and send data to OCR/LLM endpoints, but it does not declare any explicit tool scope or permission boundaries. This creates a real security gap because the agent may exercise broad file, shell, environment, and network capabilities without a machine-readable restriction layer, increasing the chance of overreach, secret exposure, or unintended outbound data transfer when handling sensitive PDFs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description states the workflow generates "中文精读总结报告", which imposes a specific language on outputs. The file does not indicate that users can choose another language or opt into Chinese-only behavior, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill metadata states it only reads local files, but the configuration clearly supports sending extracted document content to third-party OCR and summarization APIs. This creates a transparency and data-handling mismatch that can expose potentially sensitive paper contents or user-supplied material to external services without clear disclosure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This configuration includes a third-party summarization endpoint, meaning document text may be transmitted outside the local environment for processing. If users assume local-only processing, sensitive research content, unpublished manuscripts, or proprietary documents could be exposed to an external provider.

Content

Scanner excerpt · config.json (reported line 30)May include surrounding context.

json
"model": ""
      },
      "siliconflow": {
        "base_url": "https://api.siliconflow.cn/v1",
        "api_key": "",
        "model": "THUDM/GLM-4.1V-9B-Thinking"
      },

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The OpenAI-compatible endpoint enables transmission of document content to an external API service for summarization. In a paper-review workflow, this may include confidential PDFs or unpublished research, so sending data off-device without strong disclosure and consent presents a real privacy and compliance risk.

Content

Scanner excerpt · config.json (reported line 35)May include surrounding context.

json
"model": "THUDM/GLM-4.1V-9B-Thinking"
      },
      "openai-compatible": {
        "base_url": "https://api.openai.com/v1",
        "api_key": "",
        "model": "gpt-4o-mini"
      },

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The LongCat endpoint is another external destination that may receive extracted paper text during summarization. Multiple preconfigured outbound providers increase the chance that users route sensitive content to third parties without fully understanding the data-sharing implications.

Content

Scanner excerpt · config.json (reported line 45)May include surrounding context.

json
"model": "doubao-seed-2-0-lite-260215"
      },
      "longcat": {
        "base_url": "https://api.longcat.chat/openai",
        "api_key": "",
        "model": "LongCat-Flash-Chat"
      }

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction explicitly requires producing a Chinese reading report, which forces a specific language choice. Under the policy, language constraints should either be user-selectable or clearly justified as region- or compliance-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/extract_paddleocr.py (reported line 63)May include surrounding context.

python
def log(self, msg: str) -> None:
        # 进度日志走 stderr,避免污染 stdout 的 JSON 行管道
        print(msg, file=__import__('sys').stderr)
        if self.enabled:
            self._q.put(msg)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script uploads entire PDF files to an external OCR service using an API key, which can expose sensitive research papers, unpublished manuscripts, embedded metadata, or regulated content to a third party. In a paper-review workflow, users may reasonably process confidential or proprietary documents, so the absence of an explicit warning, consent step, or data-handling disclosure increases the chance of inadvertent data exfiltration.

Content

No source excerpt is available for this finding.

Tainted flow: 'data' from requests.get (line 111, network input) → requests.post (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/extract_paddleocr.py (reported line 95)May include surrounding context.

python
last_err = ''
    for i in range(3):
        with pdf_path.open('rb') as f:
            resp = requests.post(job_url, headers=headers, data=data, files={'file': f}, timeout=120)
        if resp.status_code == 200:
            return resp.json()['data']['jobId']
        # 仅保留简短且脱敏后的错误预览,避免敏感信息泄露

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest frames this as a PDF-to-summary workflow and notes that it reads config.json and prompt.md, but this file's core implementation is to spawn other programs through subprocess.run. While orchestrating helper scripts is part of a workflow, arbitrary subprocess execution is a stronger capability than the stated document summarization purpose and is not explicitly justified in the manifest.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/run_pipeline.py (reported line 44)May include surrounding context.

python
def run_capture(cmd: list[str]) -> str:
    p = subprocess.run(cmd, capture_output=True)
    enc = locale.getpreferredencoding(False) or 'utf-8'
    out = (p.stdout or b'').decode(enc, errors='replace')
    err = (p.stderr or b'').decode(enc, errors='replace')

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The runtime error strings are hard-coded in Chinese ("命令失败"), which imposes a specific language on users regardless of their locale or preferences. This is a natural-language policy concern because the file provides no opt-in, fallback, or documented reason for enforcing Chinese-only messaging.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/run_pipeline.py (reported line 55)May include surrounding context.

python
def run_with_stdin(cmd: list[str], stdin_text: str) -> str:
    enc = locale.getpreferredencoding(False) or 'utf-8'
    p = subprocess.run(cmd, input=stdin_text.encode(enc, errors='replace'), capture_output=True)
    out = (p.stdout or b'').decode(enc, errors='replace')
    err = (p.stderr or b'').decode(enc, errors='replace')
    if p.returncode != 0:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Multiple user-facing strings, defaults, window titles, output directory names, and error messages are fixed in Chinese, such as 未命名论文, 总结, and several Chinese CLI/error texts. The file does not offer locale selection or explain that the skill is intentionally limited to a Chinese-language context, which can violate language/locale choice policy.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script transmits extracted paper text to an OpenAI-compatible remote API, which expands the trust boundary beyond local PDF processing. If users believe processing is local-only, sensitive or proprietary document contents may be unintentionally disclosed to a third-party service, especially because the endpoint is configurable via config.json.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code sends extracted document text directly to an external LLM API without any explicit warning or consent mechanism in this file. In a paper-review workflow, uploaded PDFs may contain confidential research, unpublished results, or licensed material, so silent exfiltration to a remote service can cause privacy, contractual, or compliance issues.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description says the skill reads only config.json and prompt.md within the skill directory and runs scripts, which implies a tightly scoped local read pattern. In reality, this script ingests externally supplied extracted paper text from stdin and writes summary files to caller-specified output paths, expanding behavior beyond the stated read-only description of inputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script raises user-visible error messages in Chinese only ('无可提取文本' and '缺少 --pdf'). This imposes a specific language on all users without opt-in or documented locale scope, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified with a lower-bound range instead of an exact version, which makes builds non-reproducible and can unexpectedly pull in newly published releases. In a workflow skill that processes PDFs and may call external APIs, this increases supply-chain risk and makes it harder to verify whether a deployment is using a safe version.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
openai>=1.40.0
requests>=2.31.0
pdfplumber>=0.11.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
99% confidence
Finding

requests>=2.31.0 is unpinned, so installations may resolve to different versions over time, including versions later found vulnerable or behaviorally incompatible. Because this skill likely performs network access and may handle credentials or downloaded content, dependency drift in requests is more dangerous than a purely local library.

Content

Scanner excerpt · scripts/requirements.txt (reported line 2)May include surrounding context.

text
openai>=1.40.0
requests>=2.31.0
pdfplumber>=0.11.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The manifest does not pin requests, and that package has multiple published advisories across versions, so it is impossible to determine from this file whether the installed version is affected. In a skill that may make outbound HTTP requests during document-processing workflows, an unsafe requests version could expose credentials, weaken TLS verification behavior, or introduce other network security issues.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

pdfplumber is also unpinned, which permits uncontrolled version selection and weakens reproducibility and supply-chain assurance. Since the skill processes untrusted PDF inputs, using an unexpected parser version can introduce parsing flaws, denial-of-service risks, or regressions that are difficult to audit.

Content

Scanner excerpt · scripts/requirements.txt (reported line 3)May include surrounding context.

text
openai>=1.40.0
requests>=2.31.0
pdfplumber>=0.11.0

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

A batch paper summarization skill is expected to process documents and generate reports, but creating a tkinter desktop window is an extra interactive capability unrelated to the core summarization function. This may be surprising in automation or headless environments and is not mentioned in the manifest scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.