Back to skill

Security audit

HTML to Markdown

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward HTML-to-Markdown skill, with the main caution that it installs and uses a third-party MinerU CLI and token.

Install only if you are comfortable using MinerU's third-party CLI and providing a MinerU token. Prefer a pinned or isolated install when possible, avoid running it with elevated privileges, and only pass files or URLs you intend to send through the conversion workflow.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Third-Party CLI Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15-17
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Medium

bash
npm install -g mineru-open-api
# or via Go (macOS/Linux):
go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latest

Technical Analysis

The documented installation commands retrieve third-party code without pinning it to an immutable, audited version. The npm command resolves the package version available under the registry's current default distribution tag, while the Go command explicitly retrieves @latest.

Consequently, the code installed by users can change after this skill has been reviewed. If the npm publisher account, package registry, source repository, release process, or another relevant supply-chain component is compromised, a modified release could execute attacker-controlled code during installation or when the CLI is invoked.

The global npm installation also broadens exposure by installing the executable into the user's global tool environment. This finding does not establish that the current dependency is malicious; it identifies an unsafe dependency acquisition practice.

Attack Path

  1. An attacker compromises the upstream package publisher, repository, release pipeline, or registry entry.
  2. The attacker publishes a malicious version under the npm default distribution tag or as the latest Go module version.
  3. A user follows the installation instructions in SKILL.md.
  4. The package manager downloads the unreviewed, mutable release.
  5. Malicious package installation logic or the installed CLI executes with the privileges of the invoking user.
  6. The attacker can access or modify resources available to that user, including data supplied to the conversion tool and environment variables exposed to the process.

Impact Assessment

Successful exploitation could provide arbitrary code execution with ...[truncated 436 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the npm package to a specifically reviewed version, for example mineru-open-api@X.Y.Z.
  • Replace the Go @latest selector with a specifically reviewed semantic version tag.
  • Verify downloaded artifacts using trusted checksums, signatures, provenance attestations, or an approved internal package mirror.
  • Record the expected package owner, source repository, version, and integrity metadata so dependency provenance can be validated.
  • Prefer a project-local or isolated installation over a global npm installation where operationally possible.
  • Run the converter with least privilege and expose only the files, output directories, credentials, and network access required for conversion.
  • Establish a controlled update process in which new dependency versions are reviewed and tested before changing the pinned version.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.