Back to skill

Security audit

Pdf Watermark Chinese

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a local PDF watermark tool, but it advertises watermark removal even though the shipped removal function only copies the original file unchanged.

Install only if you need local PDF watermark addition. Do not rely on this skill to remove watermarks, redact identifying marks, or sanitize documents, because the removal path currently leaves the original PDF content intact. Use explicit input and output paths, keep backups, and be careful with batch processing directories.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

整体上,代码的主要目的与声明基本相关,确实围绕 PDF 水印处理展开,并支持文本和图像水印添加。但存在一个关键的描述与行为不一致:remove_watermarks() 函数并不执行水印识别或去除,仅调用 shutil.copy2 复制原文件,并在返回信息中也承认“水印移除功能需要更高级的实现”。因此,“支持移除水印”这一声明具有误导性,属于实质性能力不匹配。另一个较小的不一致是代码实现了 batch_process 及相应 CLI 批量处理命令,而声明未提及该能力。不过这属于附加功能,主 mismatch 仍是水印移除功能名不副实。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

代码的核心功能与“PDF 水印”主题相关,但实现范围明显小于声明。虽然导入了 ImageReader、tempfile 等模块,并在类注释中写到支持图像水印和移除水印,实际可执行逻辑只有 add_text_watermark 方法,以及 CLI 中的 text 子命令。没有用于图像水印的函数、参数或子命令,也没有任何移除水印的实现。因此,声明对能力范围有实质性夸大,属于描述与实际行为不一致。未发现与声明无关的额外敏感能力。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill advertises watermark removal, but the implementation merely copies the original PDF to the output path without removing anything. This is dangerous because users may rely on the tool for privacy, compliance, or redaction-like workflows and unknowingly distribute documents with the original watermark or identifying marks still present.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The docstring states that the function removes watermarks, while the code comments admit it does not and only creates a copy. This mismatch can mislead operators and downstream automation into treating the output as sanitized, causing disclosure of information that users believed had been removed.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill includes executable example code that reads and writes local files and may imply shell-capable operation, but it declares no explicit tool scope or permissions. In an agent environment, missing scope boundaries can cause the skill to run with broader-than-necessary file access, increasing the risk of unintended file modification or abuse if the skill is invoked on sensitive documents.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation examples use very broad natural-language phrases such as '移除这个PDF的水印' and '给PDF添加logo水印', which could be triggered during ordinary conversation about PDFs rather than an intentional tool-use request. In an agent system, ambiguous triggers can cause accidental execution on user files, leading to unintended document modification or destructive operations like watermark removal attempts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings and documentation exclusively in Chinese, including the module description and later CLI help/messages, with no opt-in or alternate locale support. The policy explicitly calls out forced language or locale behavior as a violation when the user is not given a choice.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · pdf_watermark.py (reported line 47)May include surrounding context.

python
# 通过fc-list查找中文字体
        try:
            result = subprocess.run(['fc-list', ':lang=zh'], 
                                  capture_output=True, text=True, timeout=5)
            if result.returncode == 0:
                for line in result.stdout.strip().split('\n'):

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module title and descriptive strings explicitly position the tool as a Chinese-enhanced utility, and all user-facing help/docstrings are written only in Chinese. Under the policy, language constraints should either offer user opt-in/choice or be clearly justified as region-specific; neither is present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.