Back to skill

Security audit

Pdf Toolkit

Security checks for vulnerabilities and agentic risk

Overview

This is a real local PDF utility, but its scripts use unsafe shell command construction and its documentation recommends a risky system-wide ImageMagick policy change.

Review carefully before installing. Use only trusted filenames and page-range inputs, avoid elevated privileges, do not put real PDF passwords directly in shell commands, and do not relax the global ImageMagick PDF policy unless you understand and can reverse the host-wide impact.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/compress.js:35
Finding

Shell Command Injection Through User-Controlled Arguments

Content
View full analysis
`"${path.resolve(f)}"`).join(' '); const outputPath = `"${path.resolve(outputFile)}"`; try { execSync(`img2pdf ${inputPaths} -o ${outputPath}`, { stdio: 'pipe' }); } catch { console.log('img2pdf unavailable; trying ImageMagick...'); try { execSync(`convert ${inputPaths} ${outputPath}`, { stdio: 'pipe' }); ``` `scripts/merge.js:25-32`: ```javascript const inputPaths = inputFiles.map(f => `"${path.resolve(f)}"`).join(' '); const outputPath = `"${path.resolve(outputFile)}"`; const command = `gs -dBATCH -dNOPAUSE -q -sDEVICE=pdfwrite -sOutputFile=${outputPath} ${inputPaths}`; try { execSync(command, { stdio: 'inherit' }); ``` `scripts/pdf2img.js:20-38`: ```javascript const inputPath = path.resolve(inputFile); const baseName = path.parse(inputFile).name; const dpi = options.dpi || 150; const format = options.format || 'png'; const outputPath = path.join(outputDir, baseName); try { let command; if (format === 'png') { command = `pdftoppm -png -r ${dpi} "${inputPath}" "${outputPath}"`; } else if (format === 'jpg') { command = `pdft ...[truncated 3910 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned Remote Package Execution During Installation

Content
View full analysis
Remediation
View remediation
install pdf-toolkit ``` 2. Document the expected registry and publisher identity so users can verify package provenance. 3. Where supported, require an integrity digest or lockfile covering the installer and its transitive dependencies. 4. Prefer a preinstalled, organization-approved installer in controlled environments rather than downloading executable code during each installation. 5. Review and update the pinned version deliberately. Do not automatically advance the pin without repeating security and compatibility checks. 6. Avoid recommending elevated privileges for the `npx` installation command. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:136
Finding

Documentation Recommends Weakening the System-Wide ImageMagick Security Policy

Content
View full analysis
# to ``` ### Technical Analysis The documentation recommends changing ImageMagick's system-wide policy from denying PDF operations to allowing both reading and writing. The existing restriction is a security boundary intended to reduce exposure to risky document coders and delegated PDF-processing components. Changing the global policy affects every ImageMagick consumer on the machine, not only this toolkit. It therefore grants broader permissions than the Skill's immediate task requires and can expose unrelated services or applications to PDF processing. The change usually requires administrative access because the policy file is under `/etc`. Although the Skill does not perform the modification automatically, users are explicitly directed to make a persistent system-wide security change. ### Attack Path 1. A user encounters a PDF conversion failure and follows the recommendation in `SKILL.md`. 2. The user edits the global ImageMagick policy with administrative privileges and enables PDF read/write access. 3. The relaxed policy remains active after the toolkit invocation and applies to unrelated ImageMagick workflows. 4. An attacker supplies a crafted PDF to any local or server-side process that uses ImageMagick under the global policy. 5. The document reaches PDF coder or delegate functionality that was previously blocked, increasing exposure to delegate misconfiguration or implementation vulnerabilities. ### Impact Assessment The direct effect is a persistent expansion of ImageMagick's permitted operations across the host. Potential consequences include: - Increased attack surface for every application usi ...[truncated 537 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents the skill as a general PDF toolbox focused on merging, splitting, compressing, and converting PDFs locally. The supplied code chunk instead performs PDF-to-text extraction, producing a .txt output via pdftotext. While 'convert PDF' could be interpreted broadly, extracting text is a specific capability not explicitly represented by the description, and the code depends on an external utility (poppler-utils) despite the description implying a self-contained local tool. This chunk also does not demonstrate the named primary functions such as merge/split/compress. Therefore, the code behavior is materially different enough from the declared purpose to flag a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

描述将该技能定位为通用“PDF工具箱”,涵盖合并、拆分、压缩、转换PDF且支持批量处理;但提供的代码片段实际只做一件事:调用本地 pdftoppm 将 PDF 页面导出为 PNG/JPG 图片。虽然这可以勉强归入“转换PDF文件”的大类,并且确实是本地执行、无需联网,但其实际功能范围明显比声明窄,且包含一个更具体但未明确说明的输出形态(转图片而非一般PDF格式转换)。代码中也没有看到批量处理、合并、拆分、压缩等实现。因此,声明与实际行为存在实质性不一致。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
node scripts/merge.js file1.pdf file2.pdf output.pdf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
node scripts/split.js input.pdf output_dir/

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
node scripts/split.js input.pdf output_dir/

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
node scripts/img2pdf.js image1.png image2.jpg output.pdf

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The installation command uses npx clawhub@latest, which fetches and executes the latest package version at install time. This creates a supply-chain risk because a compromised or malicious future release could run arbitrary code on the user's machine, and the risk is higher because the skill is presented as a local utility users may trust and install directly.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

bash
# Ubuntu/Debian
sudo apt-get install poppler-utils ghostscript imagemagick

# macOS
brew install poppler ghostscript imagemagick

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation instructs users to run file-modifying operations that create or overwrite output files and directories, but it does not warn about destructive outcomes such as clobbering existing files or writing into unintended paths. In a document-processing skill, this increases the chance of accidental data loss, especially during batch operations or when users supply unsafe output paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The examples place PDF passwords directly on the command line, which can expose secrets through shell history, process listings, terminal logs, and audit tooling. Because this skill handles local sensitive documents, encouraging insecure password handling can leak credentials and weaken document confidentiality.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code's natural-language strings, comments, errors, and CLI usage are all in Chinese, and there is no indication that the skill is intentionally limited to a Chinese-speaking audience or that users can choose another language. That creates a locale/language policy issue because the skill imposes a specific language without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file's documentation and implementation clearly indicate text extraction from PDFs using pdftotext, including writing a .txt output file and returning extracted text. The manifest description does not mention OCR or text extraction capabilities, so the implemented behavior exceeds the described functional scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a local PDF toolkit for merging, splitting, compressing, and converting PDFs, but this file implements text extraction, which is outside that stated scope. It also invokes an external program through child_process.execSync, adding command execution capability not implied by the manifest description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing description and CLI messages are written exclusively in Chinese, including usage guidance and status output. This imposes a specific language/locale on users without opt-in, which matches the policy category for language or locale constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's natural-language comments and CLI usage/output strings are entirely in Chinese, including the primary tool description and user-facing messages. This imposes a specific language on users without any opt-in or indication that the skill is intentionally region-specific, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script invokes an external utility through child_process.execSync using a shell command string built from user-controlled inputs such as dpi and output paths. Even though some arguments are quoted, this design increases attack surface and can enable command injection or unsafe execution semantics if parameters are not strictly validated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes a toolkit for merging, splitting, compressing, and converting PDF files, implying operations whose outputs remain PDFs or are standard PDF transformations. This file instead converts PDF pages into image files via pdftoppm, producing PNG/JPG outputs, which is a materially different capability not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script executes a shell command via execSync to run pdftoppm, which is a subprocess operation covered by the missing-user-warnings rule for code files. Although there are success and error logs after execution, there is no prior disclosure, confirmation, or comment warning users that the tool will invoke an external system binary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language strings such as the header comment, success/error messages, and CLI usage instructions entirely in Chinese. Under the policy rule for language/locale, forcing a specific language without user opt-in can be a policy violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s title/commentary and all CLI output strings are written in Chinese, which imposes a specific language on users. The file does not provide any opt-in, localization choice, or justification that this is a region-specific tool, so it creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/compress.js:41

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/extract-text.js:30

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/img2pdf.js:30

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/merge.js:32

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/pdf2img.js:38

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/split.js:35