Back to skill

Security audit

meta-nano-pdf

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it expands a small PDF-related purpose into persistent self-evolving agent behavior without enough scoping or user control.

Review carefully before installing. This skill may cause an agent to keep local learned state and treat PDF tasks as part of a broader self-improving orchestration loop. Only use it if you want that behavior, and consider removing or disabling the learner/persistence pieces unless they are needed.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding
The skill presents itself as a narrowly scoped PDF-related distilled skill, but the content also claims broad self-reflection, learner injection, super-agent orchestration, cross-session memory, and continuous self-evolution capabilities. That gap between declared purpose and implied behavior can mislead operators about what the skill may attempt to do, increasing the risk of unsafe delegation, hidden persistence, or unintended orchestration in a larger agent system.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The report describes a capability shift from a narrowly scoped PDF skill to a general-purpose self-evolving meta-skill with orchestration and persistent improvement behavior. This kind of scope drift is dangerous because it can enable behavior outside the user's expected trust boundary, making review, permissioning, and runtime constraints mismatch the actual capability.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
Claims of cross-session self-evolution and persistent memory introduce stateful behavior that exceeds a PDF-oriented skill's apparent purpose and can accumulate hidden instructions, preferences, or unsafe policies over time. In agent systems, unjustified persistence materially increases risk because it reduces auditability and can cause the skill to act on stale or adversarially implanted state across sessions.

Static analysis

No suspicious patterns detected.