Back to skill

Security audit

PDF-API.io

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent PDF-API.io connector, but it needs review because its fallback setup runs an unverified remote installer and its PDF rendering capability is understated.

Review before installing. Use a verified or package-manager-based oo CLI installation path instead of letting an agent run curl|bash or irm|iex automatically, and review render_pdf payloads because they may send your data to PDF-API.io and create a temporary hosted PDF URL.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:54
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis
): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ``` ``` ### Technical Analysis The setup instructions retrieve mutable scripts from external URLs and immediately execute them through Bash or PowerShell. They do not pin an installer version, verify a cryptographic signature or checksum, or provide an opportunity to inspect the downloaded content before execution. The reviewed Skill does not contain the effective installer payload. Consequently, the executed code can change after the Skill has been audited. Compromise of the hosting server, DNS or TLS delivery chain, deployment credentials, or installer publication process could turn these commands into arbitrary code-execution mechanisms. Installing the `oo` CLI is relevant only when the command is absent, but immediate execution of unverified remote content exceeds the minimum privilege and trust required for that setup task. A verified package, signed release artifact, or separately downloaded and inspected installer would provide safer alternatives. The same weakness exists on both supported platform paths: - macOS/Linux: `curl ... | bash` - Windows: `irm ... | iex` ### Attack Path 1. The `oo` command is unavailable, causing the first-time setup fallback to be used. 2. An agent or user follows the documented installation command. 3. The command requests the current installer from `cli.oomol.com`. 4. An attacker who has compromised the installer host, publication pipeline, or relevant delivery infrastructure substitutes malicious script content. 5. Bash or PowerShe ...[truncated 1087 chars]
Remediation
View remediation
/install.sh' echo ' oo-install.sh' | shasum -a 256 --check - less oo-install.sh bash oo-install.sh ``` An equivalent Windows process should download the pinned script to disk, validate its expected hash and publisher signature, present it for review, and execute it only after explicit approval. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The skill instructs users to install software via curl ... | bash, which executes a remote script directly without verification. If the install endpoint, transport, DNS, or hosting environment is compromised, this can lead to arbitrary code execution on the user's system.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest and description claim the skill is for 'searching and reading data', but the documented render_pdf action performs content generation. This mismatch can mislead upstream policy, reviewers, or users into granting the skill broader execution trust than intended, increasing the chance that write-like or cost-incurring operations are invoked without appropriate scrutiny.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.