Back to skill

Security audit

PDF to HTML

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it may send PDF contents to an external MinerU service and installs an unpinned command-line tool, so users should review it before use.

Use this skill only for PDFs you are allowed to process through MinerU/OpenDataLab, and check the provider's privacy, retention, and compliance terms before converting sensitive documents. Prefer a pinned, project-local or isolated installation of mineru-open-api, and avoid installing or running it with elevated privileges.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Global Installation of Mutable Executable Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20-22
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

bash
npm install -g mineru-open-api
# or via Go (macOS/Linux):
go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latest

Technical Analysis

Both documented installation methods retrieve mutable upstream content without pinning an audited version or verifying a checksum or signature. The Go command explicitly requests @latest, while the npm command omits a version and therefore resolves the registry's current release.

The npm command also installs the package globally. This exposes the user's broader environment to package installation behavior, including npm lifecycle scripts, and places the resulting executable in a user-wide or system-wide binary location. The installed CLI may subsequently have access to local PDF documents and the MINERU_TOKEN environment variable as part of its intended operation.

This does not establish that the current upstream packages are malicious. The vulnerability is that future installations are not reproducible and may execute content different from the dependency version that was originally reviewed.

Attack Path

  1. An attacker compromises the relevant package registry account, source repository, release process, or transitive dependency.
  2. The attacker publishes a malicious release that becomes the current npm version or the Go module version resolved through @latest.
  3. A user or agent follows the installation instructions in SKILL.md.
  4. The package manager retrieves the mutable malicious release without an integrity value or audited version constraint.
  5. Malicious package lifecycle logic or executable code runs with the permissions of the installing user.
  6. The compromised dependency can access resources available to that process, potentially including local documents, environment variables such a ...[truncated 631 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin both installation methods to a specific, reviewed release rather than using an implicit current version or @latest:
    bash
    npm install --save-exact mineru-open-api@AUDITED_VERSION
    go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@AUDITED_VERSION
    
  2. Replace AUDITED_VERSION with an actual immutable version or commit selected after security review.
  3. Prefer a project-local npm installation or an isolated container or virtual environment instead of global installation.
  4. Publish and verify cryptographic checksums or signatures for approved release artifacts.
  5. Use lockfiles where applicable and review transitive dependencies and npm lifecycle scripts.
  6. Run the conversion CLI with least privilege and provide MINERU_TOKEN only to the conversion process.
  7. Avoid using sudo or an administrative account for installation.
  8. Document the expected package publisher, repository, version, and artifact digest so users can verify provenance before execution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly supports uploading local PDFs or fetching PDFs from URLs via a token-authenticated MinerU extraction service, but it does not warn users that document contents may be transmitted to a third-party service. This creates a real privacy and data-handling risk because users may process sensitive internal, personal, or regulated documents under the assumption the conversion is purely local.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.