Back to skill

Security audit

HTML to Text

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for HTML-to-text conversion, but users should review it because selected local files or URLs may be processed through MinerU with a token and the install instructions use mutable third-party packages.

Review before installing. Use only non-sensitive HTML and public URLs unless you are comfortable with MinerU handling the content, install the CLI in an isolated environment if possible, pin and verify the package version, avoid elevated shells, and use a narrowly scoped revocable MINERU_TOKEN.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned Third-Party CLI Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:4,17-20
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

The skill directs users to install mutable versions of a third-party executable globally. The npm command has no version constraint, and the Go command explicitly selects @latest.

yaml
metadata: {"openclaw": {"emoji": "📄", "requires": {"bins": ["mineru-open-api"], "env": ["MINERU_TOKEN"]}, "primaryEnv": "MINERU_TOKEN", "install": [{"id": "npm", "kind": "node", "package": "mineru-open-api", "bins": ["mineru-open-api"], "label": "Install via npm"}, {"id": "go", "kind": "go", "package": "github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api", "bins": ["mineru-open-api"], "label": "Install via go install", "os": ["darwin", "linux"]}]}}
bash
npm install -g mineru-open-api
# or via Go (macOS/Linux):
go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latest

Technical Analysis

These commands retrieve and execute whichever package release is current at installation time, rather than a version reviewed alongside the skill. Consequently, the effective executable can change after this skill has been audited.

The npm installation is global and may run package lifecycle scripts during installation. The Go command also builds and installs code from a mutable upstream release selected through @latest. The installed CLI is subsequently expected to receive access to the MINERU_TOKEN environment variable and to process user-selected local documents. If the upstream package, publisher account, repository, release process, or transitive dependency were compromised, a malicious release could execute with the installing user's privileges.

No evidence establishes that the current upstream packages are malicious. The finding concerns the unsafe, unpinned dependency installation mechanism and the resulting supply-chain exposure.

Attack Path

  1. An attack ...[truncated 1363 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin both installation methods to a specific, reviewed release rather than relying on an implicit current npm version or Go @latest.
  2. For npm, use an exact version such as mineru-open-api@X.Y.Z, commit and verify the appropriate lockfile where applicable, and validate package integrity against a trusted checksum or registry integrity value.
  3. For Go, replace @latest with a reviewed semantic version or immutable commit identifier and verify it through the expected Go module checksum mechanism.
  4. Prefer a project-local or isolated installation over a global installation to reduce the package's reach and simplify removal.
  5. Review transitive dependencies and package lifecycle scripts before approving upgrades.
  6. Document that local files and credentials are exposed to the third-party CLI and potentially to its remote service.
  7. Provide upgrade guidance that requires security review and checksum verification before changing the pinned version.
  8. Run the converter with minimal filesystem permissions and a narrowly scoped, revocable token; avoid invoking installation or conversion commands with elevated privileges.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly supports processing local HTML files and remote URLs through a third-party service that requires authentication, but it does not clearly disclose that the HTML content may be transmitted off-host to MinerU. This creates a real data-handling and privacy risk because users may assume a local conversion workflow and unintentionally send sensitive local documents or internal URLs to an external provider.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language guidance sets ch as the default language and frames English as an override, but does not offer a neutral choice or explain why a Chinese default is required for this skill. That creates a locale preference in the skill instructions without explicit user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.