Back to skill

Security audit

nano-pdf-qtest

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a straightforward PDF editing helper, with packaging hygiene concerns but no evidence of malicious behavior in the artifacts.

Install only if you are comfortable pulling the current nano-pdf package from the configured Python package index. For safer use, install in a sandbox or least-privileged environment, review output PDFs before sharing them, and prefer a pinned, reviewed nano-pdf version if your workflow is sensitive.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:5
Vulnerability Type: Unpinned package dependency from an external package registry
Risk Level: Medium

Vulnerable Code Snippet:

json
metadata: {"clawdbot":{"emoji":"📄","requires":{"bins":["nano-pdf"]},"install":[{"id":"uv","kind":"uv","package":"nano-pdf","bins":["nano-pdf"],"label":"Install nano-pdf (uv)"}]}}

Technical Analysis

The installation metadata requests the nano-pdf package by name without specifying an exact version or an integrity hash. Consequently, the dependency resolver may install whichever release is selected from the configured package registry at installation time rather than a release whose contents were reviewed with this Skill.

Python package installation may execute package-controlled build or installation logic. If the package registry account, distribution process, package source, or configured package index is compromised, a malicious release could execute code during installation or when the nano-pdf executable is invoked.

The audited project does not bundle malicious package code, and the review found no evidence that the current nano-pdf distribution is malicious. The issue is the mutable and unverifiable dependency boundary.

Attack Path

  1. An attacker compromises the upstream package publication process, registry account, or package source used by the resolver.
  2. The attacker publishes a malicious or modified nano-pdf release.
  3. A user or automation system installs this Skill and processes the unpinned installation declaration.
  4. The resolver selects the attacker-controlled release because no exact version or cryptographic hash is required.
  5. Malicious code runs through package build or installation hooks, or later when the installed nano-pdf command is invoked.
  6. The payload operates with the filesystem, process, and network permissions of the account performing installation or execution.

...[truncated 444 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin nano-pdf to a specific version that has been independently reviewed, such as an exact package==version declaration supported by the Skill installer.
  • Require cryptographic hashes through a lock file or equivalent hash-verification mechanism.
  • Configure installation to use a trusted package index explicitly and prohibit untrusted fallback indexes.
  • Review the pinned distribution, including source distributions, wheels, build configuration, dependencies, and installation hooks.
  • Test dependency updates in an isolated environment and update the pin only after review.
  • Perform installation and PDF processing under a least-privileged account or sandbox with restricted filesystem and network access.
  • Retain dependency provenance and integrity information so deployments can reproduce the reviewed artifact.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Ae5

High
Category
analysis-evasion
Confidence
100% confidence
Finding

The file is an extremely large instruction-capable Markdown artifact that exceeds practical whole-file semantic review limits, creating an analysis blind spot. In an agent skill context, oversized prompt-bearing documents can hide malicious or policy-bypassing instructions beyond reviewer or tool coverage, so the risk comes from reduced inspectability rather than the visible lorem ipsum content itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.