T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unpinned Remote Package Execution During Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a legitimate ChatDOC helper, but it uploads local documents to a third-party API with a bearer key and has scoping weaknesses users should review first.
Install only if you are comfortable sending the selected PDF/DOC/DOCX contents to PaodingAI/ChatDOC Studio. Use a narrowly scoped API key, upload explicit files or carefully curated folders, avoid regulated or confidential documents unless approved, and prefer a pinned or verified install source.
SKILL.md:20Unpinned Remote Package Execution During Installation
scripts/knowledge-mate.mjs:204Bearer-Authenticated API Path Injection Through Unvalidated Identifiers
Referenced artifact was not completely inspected
node scripts/knowledge-mate.mjs upload-and-create \
Referenced artifact was not completely inspected
node scripts/knowledge-mate.mjs upload-and-create \
Referenced artifact was not completely inspected
node scripts/knowledge-mate.mjs upload-and-create \
Referenced artifact was not completely inspected
node scripts/knowledge-mate.mjs upload-and-create \
Referenced artifact was not completely inspected
node scripts/knowledge-mate.mjs upload-and-create \
Referenced artifact was not completely inspected
node scripts/knowledge-mate.mjs upload-and-create \
Referenced artifact was not completely inspected
node scripts/knowledge-mate.mjs upload-and-create \
Referenced artifact was not completely inspected
node scripts/knowledge-mate.mjs upload-and-create \
Referenced artifact was not completely inspected
node scripts/knowledge-mate.mjs upload-and-create \
Referenced artifact was not completely inspected
node scripts/knowledge-mate.mjs upload-and-create \
The skill declares access to environment variables and implicitly requires network access, but it does not specify an explicit tool scope such as permissions or allowed-tools. In an agent environment, that weakens enforcement boundaries and can allow the skill to be invoked with broader capabilities than users or operators expect, especially since it reads a bearer API key and uploads local files to a remote service.
The skill encourages uploading local PDF/DOC/DOCX files to a remote API but does not clearly warn users that document contents leave the local environment and are transmitted to a third-party service. This creates a meaningful privacy and data-handling risk because users may upload sensitive internal or regulated documents without informed consent.
Using npx skills add PaodingAI/skills without a pinned version makes installation non-reproducible and exposes users to supply-chain risk if the upstream package changes or is compromised. A later malicious or broken release could be fetched at install time without any review, altering skill behavior or introducing data exfiltration.
The script reads local PDF/DOC/DOCX files and uploads their full contents to a third-party remote service, but it provides no explicit runtime disclosure, confirmation, or data-handling warning before transmission. In an agent-skill context, this increases the risk of unintentional exfiltration of sensitive local documents because automation may invoke the upload path with broad directory inputs and users may not realize content leaves the local environment.
The client reads PAODINGAI_API_KEY from the environment, which is a sensitive credential access path covered by the warning requirement for code files. The code explains that the variable is required if absent, but it does not provide a user disclosure about credential use or handling when the skill runs.
No suspicious patterns detected.