Back to skill

Security audit

HTML to HTML

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent MinerU HTML-cleanup helper, but users should treat submitted pages/files and the MinerU token as sensitive.

Install only if you are comfortable using MinerU's external service for the pages or HTML files you submit. Avoid sending confidential, regulated, proprietary, or internal-only HTML unless your organization approves it, keep MINERU_TOKEN out of logs and source control, and prefer a pinned or isolated install of mineru-open-api when practical.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Warning
Location
SKILL.md:26
Finding

Undisclosed External Processing of Local HTML Documents

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Mutable Third-Party Tool Installation

Content
View full analysis
Remediation
View remediation
`. 2. Pin the Go dependency to a specific reviewed semantic version rather than `@latest`; for stronger reproducibility, document the reviewed commit. 3. Publish expected package checksums or signature-verification instructions where supported. 4. Review package provenance, maintainers, release signatures, and installation scripts before updating the pinned version. 5. Avoid global installation where feasible. Prefer a locked, isolated project environment or a controlled container. 6. Use package lockfiles or equivalent dependency manifests for reproducible installations. 7. Apply updates through an explicit review process rather than automatically tracking the newest release. 8. Run the client with a minimally privileged user and expose only the input files, output directory, network access, and environment variables required for the task. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly encourages crawling remote web pages through a third-party service but does not disclose that the target URL and fetched page content are sent to MinerU infrastructure. Users may assume processing is local and unintentionally transmit sensitive URLs, internal endpoints, or proprietary page content to an external provider.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The authentication instructions show how to set MINERU_TOKEN but do not warn users that API tokens are sensitive secrets that can leak via shell history, shared terminals, screenshots, CI logs, or committed env files. This omission increases the chance of accidental credential exposure and subsequent misuse of the MinerU account/API access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.