other
- Location
SKILL.md:26- Finding
Undisclosed External Processing of Local HTML Documents
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent MinerU HTML-cleanup helper, but users should treat submitted pages/files and the MinerU token as sensitive.
Install only if you are comfortable using MinerU's external service for the pages or HTML files you submit. Avoid sending confidential, regulated, proprietary, or internal-only HTML unless your organization approves it, keep MINERU_TOKEN out of logs and source control, and prefer a pinned or isolated install of mineru-open-api when practical.
SKILL.md:26Undisclosed External Processing of Local HTML Documents
SKILL.md:15Unpinned Mutable Third-Party Tool Installation
The skill explicitly encourages crawling remote web pages through a third-party service but does not disclose that the target URL and fetched page content are sent to MinerU infrastructure. Users may assume processing is local and unintentionally transmit sensitive URLs, internal endpoints, or proprietary page content to an external provider.
The authentication instructions show how to set MINERU_TOKEN but do not warn users that API tokens are sensitive secrets that can leak via shell history, shared terminals, screenshots, CI logs, or committed env files. This omission increases the chance of accidental credential exposure and subsequent misuse of the MinerU account/API access.
No suspicious patterns detected.